T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:93- Finding
Remote Installer Is Downloaded and Piped Directly Into a Shell
- Content
View full analysis
/dev/null; then # Try sourcing uv env if [[ -f "$HOME/.local/bin/env" ]]; then source "$HOME/.local/bin/env" fi if ! command -v uvx &> /dev/null; then print_error "uvx not found. Install uv with: curl -LsSf https://astral.sh/uv/install.sh | sh" exit 1 fi fi ``` ### Technical Analysis The documented command retrieves a mutable shell script from an external host and sends it directly to `sh`. There is no version pinning, checksum validation, signature verification, or opportunity to inspect the downloaded content before execution. Although `astral.sh` appears to be the expected upstream source for the declared `uv` dependency, this construction makes the effective code executed by users dependent on the response returned at execution time. Compromise of the upstream distribution service, DNS resolution, TLS trust chain, or release infrastructure could replace the installer after the Skill has been audited. The command is not automatically executed by `safe-install.sh`; it is presented as an instruction and error-message recommendation. Nevertheless, following the documented installation procedure creates a remote code-execution channel. ### Attack Path 1. An attacker compromises the installer host, its deployment infrastructure, DNS resolution, or another trusted component in the delivery path. 2. The attacker modifies the response returned for `https://astral.sh/uv/install.sh`. 3. A user follows the requirement printed in `SKILL.md` or the error message in `safe-in ...[truncated 701 chars]- Remediation
View remediation
