T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:21- Finding
Unpinned Remote Repository Retrieval Followed by Local Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is clearly meant to manage Yuzhua, but it downloads and runs mutable external code and its stop command can force-kill unrelated local processes.
Install only if you trust the Yuzhua upstream repository and understand that the skill will run code from the current checkout, not a pinned reviewed release. Review YUZHUA_REPO_URL and YUZHUA_HOME before use, and be careful with stop.sh because it can kill any process listening on the configured port, especially the default 8080.
scripts/install.sh:21Unpinned Remote Repository Retrieval Followed by Local Execution
scripts/stop.sh:11Port-Based Stop Logic Can Terminate Unrelated Processes
The declared description promises a broader management skill: install, start, stop, and health-check Yuzhua. However, this code chunk implements only installation/update preparation steps. It interacts with git and the local filesystem to clone or update the repository and prepare environment files, but contains no logic to launch Yuzhua, stop it, or verify runtime health. This is a material description-to-behavior mismatch because key advertised capabilities are absent from the supplied code.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
prepare_env() {
if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
log "Created .env from .env.example"
log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
}
prepare_env() {
if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
log "Created .env from .env.example"
log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
prepare_env() {
if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
log "Created .env from .env.example"
log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
fi
}
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
prepare_env() {
if [ ! -f "${YUZHUA_HOME}/.env" ] && [ -f "${YUZHUA_HOME}/.env.example" ]; then
cp "${YUZHUA_HOME}/.env.example" "${YUZHUA_HOME}/.env"
log "Created .env from .env.example"
log "Please edit ${YUZHUA_HOME}/.env if token is not auto-discovered."
fi
}
The skill advertises shell-driven install/start/stop/health-check behavior but does not declare any explicit tool scope or permissions. In systems that rely on manifest-declared boundaries, this creates an authorization gap: an agent may invoke shell-capable scripts without clear user-visible restrictions, increasing the chance of unintended code execution or repository/script abuse.
No suspicious patterns detected.