T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:31- Finding
Execution of Unpinned Code Retrieved from a Remote Repository
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31–48
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash git clone https://github.com/JayeGT002/Tavily-Search-Skill.git tavily-search-skill cd tavily-search-skillThe installation workflow later executes the remotely retrieved script:
bash ./search.sh "test"Technical Analysis
The installation instructions clone the mutable default branch of a remote Git repository without specifying a reviewed commit hash or verifying a cryptographic signature or checksum. The workflow then executes
search.shfrom that repository.Consequently, the code executed during installation is not necessarily the same code contained in the audited artifact. The effective payload can change after review if the upstream repository is modified. This creates a time-of-check-to-time-of-use supply-chain weakness and provides a direct remote code execution channel.
The workflow also instructs the user to create an
apikeyfile before running the verification command. A malicious replacement forsearch.shcould therefore read and exfiltrate that credential when executed.Attack Path
- An attacker compromises the upstream repository, its owner account, or another mechanism capable of changing its default branch.
- The attacker replaces or modifies
search.shwith malicious shell commands. - An agent follows the documented installation workflow and clones the current default branch without pinning a commit.
- The user supplies a Tavily API key, which is stored in the skill directory as
apikey. - The agent runs
./search.sh "test"as instructed. - The modified script executes with the installing user's privileges and can access the API key and other resources available to that user.
Impact Assessment
Successful exploitation permits arbitrary command execution with the privileges ...[truncated 625 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the installation to a specific, reviewed commit hash rather than cloning and executing the mutable default branch.
- Prefer signed, immutable releases and verify the maintainer's signature before using the downloaded content.
- Publish an expected cryptographic checksum for the release archive or entry script and verify it before execution.
- Inspect the checked-out commit and confirm that it matches the reviewed version before running any script.
- Create or expose the API key only after code verification, and avoid placing credentials in a directory controlled by newly downloaded code.
- Run the initial verification in a restricted environment with minimal filesystem access, a sanitized environment, and limited network permissions.
- Document an explicit trusted commit or release version in
SKILL.md, for example:
bash git clone https://github.com/JayeGT002/Tavily-Search-Skill.git tavily-search-skill cd tavily-search-skill git checkout --detach EXPECTED_REVIEWED_COMMIT test "$(git rev-parse HEAD)" = "EXPECTED_REVIEWED_COMMIT" || exit 1The expected commit should be independently authenticated; merely recording an attacker-controlled commit from the remote repository is insufficient.
