T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:62- Finding
Mutable Remote Installation Scripts Are Downloaded and Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This cloud document-extraction skill is broadly useful, but its installation and documentation give it more risky authority than a certificate-only extractor should need.
Review before installing. Use this only if you trust Laiye ADP and are allowed to send certificate images and extracted business data to its cloud service. Prefer a pinned, verifiable release or reviewed package install instead of curl-to-shell or PowerShell Invoke-Expression, protect the ADP API key, and do not allow the agent to use custom-app management or arbitrary document-processing commands unless you explicitly intend that broader access.
SKILL.md:62Mutable Remote Installation Scripts Are Downloaded and Executed Without Verification
SKILL.md:57Unpinned Global npm Dependency Installation Creates Supply-Chain Risk
The explicit | bash pattern is a classic chaining abuse primitive: it combines network retrieval with immediate interpreter execution, eliminating review and integrity checks. In a skill context, this is especially risky because agents or users may copy-paste the command verbatim, leading to one-step remote code execution.
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
The README describes a broad, general-purpose ADP CLI with capabilities spanning arbitrary document parsing, extraction, automation workflows, and agent use, which materially exceeds the narrowly declared skill purpose of organization-code-certificate recognition and extraction. This scope mismatch is dangerous because an agent or user may grant the skill far broader trust and operational latitude than intended, enabling unintended data access, transmission, or task execution outside the declared business function.
The explicit curl ... | bash pattern is a classic command-chaining anti-pattern that executes unverified remote content directly in a shell. In the context of an AI skill README, this is especially risky because users or agents may copy it verbatim, leading to immediate arbitrary code execution if the fetched content is malicious or altered.
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
Including custom application creation, update, and deletion commands in a certificate-recognition skill gives the skill mutation and lifecycle-management capabilities unrelated to simple field extraction. In an agent context, this broadens the attack surface from passive document processing to changing server-side configurations and apps, which could be abused to alter extraction logic, destroy configurations, or pivot into wider platform administration.
The specific use of curl ... | bash creates a high-risk command-chaining pattern where untrusted network content is immediately executed. This makes compromise easy to weaponize and gives users no chance to validate the retrieved content before code execution.
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
The README describes a broad, general-purpose ADP CLI for arbitrary document parsing, extraction, app management, and agent use, which does not match the manifest’s narrow claim of a skill limited to Chinese organization code certificate recognition. This scope mismatch is dangerous because users or agents may grant broader trust, capabilities, and data access than intended, enabling misuse of the skill as a generic document-processing wrapper rather than a constrained extractor.
The README instructs users to process remote URLs and export results locally, but does not clearly warn that document contents may be transmitted to a third-party cloud service or persisted to disk. This creates privacy and compliance risk, especially for sensitive business documents, because operators may unknowingly exfiltrate data externally or leave extracted results in local files and directories.
The README advertises custom application creation, update, deletion, and AI-generated schema features that materially exceed the stated purpose of certificate recognition/extraction. In an agent skill context, exposing undocumented broader functionality increases the chance of capability confusion and abuse, allowing the skill to be repurposed for arbitrary extraction workflows beyond what operators believe they approved.
The README instructs users to process local and remote documents and export results, but does not clearly warn that document contents are transmitted to a public cloud service and that extracted outputs may be written to local disk. For document-processing skills handling business records and certificates, this omission can lead to accidental disclosure of sensitive data and unsafe storage practices by users or downstream agents.
Support for processing arbitrary remote URLs is broader than the declared certificate-extraction use case and enables the skill to fetch or submit documents from external locations outside a controlled local workflow. In practice this can increase data exfiltration, misuse of third-party content, and unintended processing of sensitive remote resources, especially when an agent follows untrusted inputs.
The skill instructs users to upload certificate images and extracted data to an external ADP cloud service but does not clearly and prominently disclose that documents leave the local environment or explain the privacy/compliance implications. Because these files may contain organization identifiers, addresses, and legal representative information, users could inadvertently transmit sensitive data to a third party without informed consent.
The file claims to document a skill for 组织机构代码证 extraction, but these sections instruct the user to identify and cache an app for 开户许可证 instead. This is an active contradiction in the documentation about which extraction app should be used, and could cause the agent or user to invoke the wrong capability.
Several later sections switch from 组织机构代码证 to 营业执照, 开户许可证, and 驾驶证 when describing pricing, app_id reuse, PII handling, and empty-field behavior. These are direct documentation contradictions that blur the intended skill and could cause misuse of the wrong extraction app or wrong data-handling assumptions.
The README recommends installing via a shell command that fetches a remote script directly from GitHub and executes it. This is dangerous because any compromise of the repository, branch, network path, or referenced script immediately becomes arbitrary code execution on the user’s machine.
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
The README recommends installing via a shell pipeline that fetches a remote script and executes it immediately. This is dangerous because compromise of the upstream source, repository, CDN path, or transport endpoint would result in arbitrary code execution on the user's machine with the privileges of the invoking user.
# Method 2: Shell script (Linux / macOS, when npm is not available)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
The description and operational instructions are presented entirely in Chinese, with no indication that users may choose another language or locale. Under the language/locale policy rule, forcing a single language without opt-in can be a natural-language policy concern unless clearly justified as region-specific.
The skill recommends installing software by fetching a remote script from GitHub and executing it directly via the shell. This bypasses review and integrity verification; if the script source, repository, network path, or upstream account is compromised, arbitrary code will run on the user's machine with the user's privileges.
# 方法 2: Shell 脚本(Linux / macOS,无 npm 环境时使用)
curl -fsSL https://raw.githubusercontent.com/laiye-ai/adp-cli/main/scripts/adp-init.sh | bash
The text says the skill returns '6个关键字段' and '以下6个字段', but the JSON example and field table enumerate 8 fields. This is not merely incomplete documentation; it actively contradicts the described output contract and can mislead downstream integrators about the skill's actual behavior.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
1. Licensing
1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
1. Licensing
1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
1. Licensing
1.1 Free Use and Distribution: The Licensor grants the Licensee a non-transferable, non-exclusive right to freely use, copy, publish, and distribute copies of the Product for non-commercial purposes. The aforementioned "non-commercial purposes" include, but are not limited to:
Personal learning, research, teaching, and evaluation.
Technical exchanges within academic institutions or open-source communities, non-profit projects.
Integration or demonstration in non-commercial products or services.
Skill's behavior or capabilities extend beyond its stated purpose. Scope creep allows an agent to perform actions unrelated to its documented functionality, increasing the attack surface.
4. Disclaimer of Warranties
THE PRODUCT IS PROVIDED "AS IS", WITHOUT WARRANTIES OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO: THE LICENSOR DOES NOT WARRANT THAT THE PRODUCT IS FREE FROM ERRORS, BUGS, WILL OPERATE PROPERLY, OR IS SUITABLE FOR A PARTICULAR PURPOSE; THE LICENSOR DOES NOT WARRANT THAT USE OF THE PRODUCT WILL NOT INFRINGE UPON THIRD-PARTY RIGHTS; THE LICENSOR SHALL NOT BE LIABLE TO THE LICENSEE OR ANY THIRD PARTY FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, OR PUNITIVE DAMAGES ARISING FROM THE USE OF THE PRODUCT.
5. Termination
No suspicious patterns detected.