T03 · Remote Payload Retrieval and Execution
- Location
scripts/adopt.sh:25- Finding
Execution of Mutable Third-Party GitHub Actions Workflows
- Content
View full analysis
Vulnerability Details
File Location:
scripts/adopt.sh:25-28, 89-106
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighThe adoption process forks a mutable external repository, enables unrestricted GitHub Actions, and immediately dispatches a workflow from that repository.
bash # Map animal to source repo case "$ANIMAL" in monkey) SOURCE_REPO="forkZoo/forkMonkey" ;; cat) SOURCE_REPO="forkZoo/forkCat" ;; dog) SOURCE_REPO="forkZoo/forkDog" ;; lion) SOURCE_REPO="forkZoo/forkLion" ;; esacbash # Enable GitHub Actions (they're disabled by default on forks) echo "⚡ Enabling GitHub Actions..." curl -s -X PUT \ -H "Authorization: token $GITHUB_TOKEN" \ -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/$GITHUB_USER/$REPO_NAME/actions/permissions" \ -d '{"enabled": true, "allowed_actions": "all"}' > /dev/null # Trigger the genesis workflow if it exists echo "🐣 Initializing your pet..." curl -s -X POST \ -H "Authorization: token $GITHUB_TOKEN" \ -H "Accept: application/vnd.github.v3+json" \ "https://api.github.com/repos/$GITHUB_USER/$REPO_NAME/actions/workflows/genesis.yml/dispatches" \ -d '{"ref": "main"}' 2>/dev/null || trueTechnical Analysis
The effective workflow payload is not included in the audited project. It is obtained by forking one of four externally maintained repositories at its current, mutable state. No commit SHA, workflow digest, signature, or allowlisted workflow contents are verified before execution.
The setting
"allowed_actions": "all"also permits the forked workflows to use arbitrary actions rather than a restricted set of reviewed actions. Consequently, the code that executes in GitHub Actions can change after this Skill has passed review.This behavior is directly related to pet initialization, but it exceeds minimum privilege because all Actions are enab ...[truncated 1426 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each supported source repository to a reviewed commit SHA and verify the forked default branch matches that SHA before enabling Actions.
- Retrieve and inspect the exact workflow files and referenced local actions before dispatching them.
- Require explicit user confirmation that identifies the upstream repository, commit SHA, workflow, and requested permissions.
- Replace
"allowed_actions": "all"with selected-action or organization-level allowlists. - Pin third-party actions inside workflows to immutable full commit SHAs rather than tags or branches.
- Configure the repository’s default workflow token to read-only and grant write permissions only to specific jobs that require them.
- Do not automatically execute the workflow if integrity validation fails or the upstream commit differs from the reviewed version.
