T03 · Remote Payload Retrieval and Execution
- Location
install.sh:78- Finding
Mutable Remote Code and Dependencies Are Downloaded and Executed
- Content
View full analysis
&1 | tail -1 else info "Cloning llm-council to $INSTALL_DIR..." mkdir -p "$(dirname "$INSTALL_DIR")" git clone https://github.com/jeadland/llm-council.git "$INSTALL_DIR" fi cd "$INSTALL_DIR" # ── Backend: uv sync ────────────────────────────────────────────────────────── info "Running uv sync (Python backend)..." uv sync 2>&1 | tail -5 # ── Frontend: npm ci ────────────────────────────────────────────────────────── info "Running npm ci (frontend)..." cd frontend npm ci --silent cd .. ``` The retrieved backend is later executed: ```bash uv run python -m backend.main > "$BACKEND_LOG" 2>&1 & ``` ### Technical Analysis The installer clones or updates the current state of an external Git repository without pinning a reviewed commit, verifying a cryptographic checksum, or validating a signed release. Consequently, the effective code executed by the Skill can change after the Skill package itself has been audited. The installer also resolves Python and npm dependencies and may execute package installation hooks. Although `npm ci` uses a lockfile if one is present in the remote repository, that lockfile is itself mutable because the repository is not pinned. The reviewed Skill package does not contain the retrieved source or dependency manifests, so their runtime behavior cannot be established from this audit. This is not the pre-scan-reported `curl | bash` pattern: no such pipeline exists in `ask-council.sh`. Nevertheless, cloning mutable code and immediately installing and running it creates an equivalent remote code execution trust boundary. ### Attack Path 1. The upstr ...[truncated 1175 chars]- Remediation
View remediation
