T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:64- Finding
Mutable Remote Installer Is Executed Directly by Bash and PowerShell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:64-69
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bashpowershell irm https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.ps1 | iexTechnical Analysis
These installation alternatives retrieve scripts from the mutable
mainbranch of an external GitHub repository and immediately pass the responses to a command interpreter. Neither command pins an immutable commit or release, verifies a cryptographic signature or checksum, nor permits inspection before execution.The repository organization is consistent with the claimed vendor, but that does not remove the risk arising from mutable remote execution. Compromise of the repository, maintainer account, branch, release workflow, or delivered response would allow the effective installer payload to change after this Skill was audited.
Immediate remote script execution is not the minimum privilege required to install a document-processing CLI. The script inherits all permissions of the invoking user and is not constrained to installation-related operations.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or another part of the script delivery process.
- The attacker modifies
scripts/adp-init.shorscripts/adp-init.ps1on themainbranch. - A user or AI Agent follows the installation instructions in
SKILL.md. curlorirmretrieves the attacker-controlled response.- Bash or PowerShell executes the response immediately without local inspection or integrity verification.
- The payload operates with the invoking user's privileges and may access credentials, documents, configuration files, and writable system resources.
Impact Assessment
Successful exploitation provides arbitrary ...[truncated 436 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bashandirm | iexinstallation instructions. - Pin the installer to an immutable, reviewed release or commit rather than
main. - Download the installer to a local file before execution.
- Publish and require verification of a SHA-256 checksum and, preferably, a cryptographic publisher signature.
- Display or otherwise make the downloaded script available for inspection before requesting explicit user approval to run it.
- Prefer signed release packages or a version-pinned package-manager installation.
- Run installation with ordinary user privileges and request elevation only for a narrowly defined operation that demonstrably requires it.
- Remove all
