T03 · Remote Payload Retrieval and Execution
- Location
references/ONBOARDING.md:240- Finding
Unverified Remote Installer Is Piped Directly into a Shell
- Content
View full analysis
Vulnerability Details
File Location:
references/ONBOARDING.md:240
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -LsSf https://astral.sh/uv/install.sh | shTechnical Analysis
The troubleshooting instructions download a mutable remote script and immediately pass it to
sh. The script is not pinned to a specific version, saved for inspection, or verified using a cryptographic signature or trusted checksum.Although the URL appears to belong to the legitimate
uvproject and HTTPS protects the connection in transit, the effective code being executed may change after this Skill has been reviewed. Compromise of the distribution server, publishing process, domain, or applicable TLS trust chain could therefore turn this instruction into arbitrary code execution.This behavior is not necessary for the Skill's core commit-indexing functionality. Installing
uvmay be a prerequisite, but doing so through an unverified remote shell pipeline exceeds the minimum safe execution mechanism needed to satisfy that prerequisite.Attack Path
- A user attempts to configure the Skill on a system where
uvis unavailable. - The Agent follows the mandatory onboarding troubleshooting instructions.
curlretrieves the current response fromhttps://astral.sh/uv/install.sh.- The response is streamed directly to
shwithout inspection or integrity verification. - If the remote distribution channel has been compromised, attacker-controlled shell commands execute with the privileges of the user running the command.
- Those commands can access or modify any files and credentials available to that user and may establish additional persistence.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoking user's account. The resulting scope may include:
- Reading and modifying source repositori ...[truncated 543 chars]
- A user attempts to configure the Skill on a system where
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstruction. - Prefer installation through a trusted operating-system package manager or another repository with authenticated package metadata.
- If the upstream installer must be used:
- Pin a specific installer release or immutable artifact.
- Download it to a local file without executing it.
- Verify a publisher signature or a SHA-256 checksum obtained through a separately authenticated channel.
- Allow the user to inspect the downloaded script.
- Request explicit confirmation before execution.
- Execute it without elevated privileges.
- Document the files and configuration the installer is expected to modify.
- In Agent instructions, require explicit user authorization before downloading or executing any external installer.
- Remove the
