T03 · Remote Payload Retrieval and Execution
- Location
scripts/setup.sh:15- Finding
Mutable Remote Installer Is Piped Directly Into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a disclosed crypto-trading helper, but it asks users to run mutable remote installation code and unpinned trading dependencies before handling exchange keys and trade execution.
Review before installing. Use a fresh virtual environment or container, install uv through a trusted pinned method instead of running the provided curl | sh path, pin the external repository and Python dependencies, start with BINANCE_TESTNET=true, and use Binance keys that cannot withdraw funds. Enable WeChat notifications only if you are comfortable sending trading and account activity to that webhook provider.
scripts/setup.sh:15Mutable Remote Installer Is Piped Directly Into a Shell
scripts/setup.sh:35Dependencies Are Installed Without Version or Integrity Pinning
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
在项目根目录创建 .env 文件:
cp .env.example .env
编辑 .env,填入:
Using 'curl ... | sh' is especially dangerous because it combines network retrieval and shell execution in one step without validation. In the context of a crypto-trading agent, this is more sensitive because users may run the installer on systems that later hold exchange API keys or trading infrastructure, increasing the consequences of compromise.
# 检测 uv 是否安装
if ! command -v uv &> /dev/null; then
echo "📦 安装 uv..."
curl -LsSf https://astral.sh/uv/install.sh | sh
source "$HOME/.local/bin/env" 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
fi
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo ""
echo "下一步:"
echo "1. 复制环境配置文件:"
echo " cp .env.example .env"
echo ""
echo "2. 编辑 .env,填入你的 API Key:"
echo " nano .env"
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
echo ""
echo "下一步:"
echo "1. 复制环境配置文件:"
echo " cp .env.example .env"
echo ""
echo "2. 编辑 .env,填入你的 API Key:"
echo " nano .env"
The skill documents shell commands and operational workflows but does not declare any explicit tool scope such as allowed tools or permissions. In an agent setting, this increases the chance that a host or user grants broader shell access than intended, enabling cloning repos, installing packages, or running trading-related commands without clear confinement.
The manifest description uses Chinese-only text to describe the skill's purpose and scope. Under the policy, forcing a specific language without user choice is a natural-language policy violation unless the locale constraint is documented and justified, which is not present here.
The skill advertises automatic WeChat notifications for trading signals, executions, errors, and account status without clearly warning that sensitive financial and account activity data may be sent to a third-party webhook endpoint. This can lead to unintended disclosure of trading behavior, positions, balances, and operational metadata outside the local environment.
The user-facing comments and echo output are written in Chinese throughout the script, including setup instructions and next steps. This imposes a specific language on users without opt-in or justification that the skill is intended only for a Chinese-speaking or region-specific audience.
The script header comments and the user-facing echo message are in Chinese, which imposes a specific language on users. The policy allows locale constraints only when users are given a choice or the restriction is clearly justified, neither of which appears here.
The script downloads and executes a remote installer from the network at runtime, which creates a supply-chain and remote code execution risk. If the remote host, TLS trust chain, or delivery path is compromised, arbitrary code will run on the user's machine during setup.
# 检测 uv 是否安装
if ! command -v uv &> /dev/null; then
echo "📦 安装 uv..."
curl -LsSf https://astral.sh/uv/install.sh | sh
source "$HOME/.local/bin/env" 2>/dev/null || true
export PATH="$HOME/.local/bin:$PATH"
fi
No suspicious patterns detected.