T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:119- Finding
Remote Installers Are Downloaded and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 119-123 and 147-151
Vulnerability Type: Unverified remote executable retrieval and execution
Risk Level: HighVulnerable Code
powershell $f = "$env:TEMP\python-installer.exe" Invoke-WebRequest "https://www.python.org/ftp/python/3.12.10/python-3.12.10-amd64.exe" -OutFile $f Start-Process $f -ArgumentList "/quiet InstallAllUsers=0 PrependPath=1 Include_pip=1" -Wait Remove-Item $fpowershell $f = "$env:TEMP\git-installer.exe" Invoke-WebRequest "https://github.com/git-for-windows/git/releases/download/v2.49.0.windows.1/Git-2.49.0-64-bit.exe" -OutFile $f Start-Process $f -ArgumentList "/VERYSILENT /NORESTART /NOCANCEL /SP- /CLOSEAPPLICATIONS /RESTARTAPPLICATIONS /COMPONENTS=icons,ext\\reg\\shellhere,assoc,assoc_sh" -Wait Remove-Item $fTechnical Analysis
The Skill instructs the Agent to retrieve native Windows executables and launch them immediately without checking a cryptographic digest or validating the Authenticode publisher signature. HTTPS protects the transport connection but does not independently establish that the downloaded artifact is the exact release reviewed by the Skill author.
The highlighted Git download is hosted by the official
git-for-windows/gitGitHub project rather than a pastebin. Nevertheless, the release asset remains an external executable whose contents could change through repository compromise, account compromise, release-asset replacement, CDN compromise, malicious proxying, or an unexpected redirect.The installers run as the current user. The Python command correctly requests a per-user installation, but it modifies
PATH. The Git command also installs shell integration and file associations and permits closing or restarting applications. Those additional modifications are not the minimum changes needed merely to provide Git for dependency installation.Attack Path
- An attacker comp ...[truncated 987 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not automatically install system prerequisites without explicit, informed user consent.
- Publish a trusted SHA-256 digest for each exact installer and verify it before execution with
Get-FileHash. - Validate the Authenticode signature with
Get-AuthenticodeSignature, require a valid signature, and verify the expected publisher. - Reject redirects to unexpected hosts and fail closed if any verification step fails.
- Prefer an existing package manager with integrity and publisher validation where available.
- Remove unnecessary Git components such as shell integration and file associations unless the user explicitly requests them.
- Keep installation per-user and avoid elevation.
- Retain sufficient audit output to identify the final URL, digest, signer, and installer exit status.
