T03 · Remote Payload Retrieval and Execution
- Location
README.md:31- Finding
Unverified Remote Installer Is Executed Directly by the Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The customer-service skill content is mostly coherent, but its installers add unattended auto-updates and execute mutable remote code in ways users should review carefully before installing.
Install only after reviewing the scripts locally. Prefer a pinned release or verified archive, avoid running the one-line remote shell commands, and remove or decline the cron/scheduled-task auto-update behavior unless you explicitly want the skill to update itself every day from GitHub. Do not run the installer with administrator or root privileges.
README.md:31Unverified Remote Installer Is Executed Directly by the Shell
install.sh:47Unix Installer Establishes Unattended Daily Code Updates Through Cron
install.ps1:42Windows Installer Establishes Unattended Daily Code Updates Through Task Scheduler
install.sh:38Unix Installer Recursively Deletes an Existing Skill Directory Without Confirmation
install.ps1:28Windows Installer Recursively Deletes an Existing Skill Directory Without Confirmation
The | bash and PowerShell iex pattern is a classic command-chaining anti-pattern that converts untrusted network content directly into code execution with no inspection barrier. In this skill context, the install commands appear in a public-facing README for a customer-service skill, so routine users may copy/paste them without security scrutiny, greatly increasing the chance of compromise.
# macOS / Linux
curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# Windows(PowerShell)
powershell -c "irm https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.ps1 | iex"
The declared description presents a customer-service skill focused on answering product and commerce-related user queries. However, the supplied code does not implement any customer-service logic, product handling, or query processing. Instead, it is purely an installation/update shell script that downloads code from GitHub, writes into the user's local skills directory, and persists a cron-based auto-update task. These are material behaviors not reflected in the declared purpose or permissions. While installation can be a supporting detail for distributing a skill, this code chunk itself has a different primary function and includes undeclared system-modifying capabilities, especially cron persistence.
The declared description presents an end-user-facing e-commerce customer service skill for trash bags and related products. However, the supplied code is not implementing customer support logic, recommendation logic, pricing/shipping/after-sales handling, or any user-triggered conversational behavior. It is a test script whose primary purpose is to verify that the skill package contains required files and expected text patterns. This is a materially different primary purpose from the declared description, so it should be flagged as a mismatch.
One-word triggers like '推荐', '价格', '优惠', '快递', '退', and '质量' are extremely collision-prone and likely to match normal conversation across many domains. In an agent environment, this can hijack routing, force irrelevant persona/instructions, and interfere with safer or more appropriate skills, increasing the risk of misclassification and unintended behavior.
Using curl ... | bash enables immediate execution of remote code without inspection, validation, or provenance checks. This is especially dangerous because the same installer already performs filesystem modification and persistence setup, so compromise of the source can directly lead to arbitrary code execution and durable host changes.
# 奕辰垃圾袋(Yichen Trash Bag)Skill · 一键安装脚本
# ============================================================
# 用法(客户只需运行这一行):
# curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# ============================================================
set -e
The trigger list includes "垃圾袋" as a standalone activation keyword, which is a generic product term likely to appear in ordinary shopping conversations unrelated to this specific skill. The README does not provide limiting context, exclusion conditions, or negative examples to distinguish when the skill should activate versus when it should not.
The README instructs users to execute remotely fetched scripts directly with bash and iex without any integrity verification, review step, or warning. This creates a direct path for arbitrary code execution if the upstream repository, network path, or referenced script is compromised, and README-driven copy/paste makes exploitation more likely.
Without declared permissions the skill's intent is opaque and cannot be validated.
The trigger list includes very broad, everyday shopping terms such as '垃圾袋', '一次性用品', and related generic product words. This can cause the skill to activate outside its intended context, overriding other skills or injecting brand-specific sales behavior into unrelated conversations, which is a prompt-routing integrity issue.
The skill instructs the AI to act as a Chinese-language storefront客服 using prescribed Chinese phrasing such as “亲~” and “咱家,” but it does not state that users can choose another language. Under the policy, forcing a specific language without opt-in is a natural-language policy issue unless the locale limitation is explicitly documented and justified.
The installer forcefully deletes any existing skill directory and then installs replacement content, while also registering persistence, all without prompting the user or warning about these system modifications. This can cause data loss, overwrite local changes, and silently establish long-lived behavior that the user did not knowingly approve.
The installer registers a persistent Windows scheduled task to run daily, which goes beyond a one-time skill installation and creates ongoing code execution on the host. For a simple e-commerce customer-service skill, this persistence is not clearly necessary and increases the attack surface because any future repository compromise or unintended update will be executed automatically.
The script creates a daily auto-update mechanism that executes git pull from a remote repository without meaningful trust controls such as version pinning, signature verification, or user approval. This is dangerous because it turns the installed skill into a continuously changing codebase and allows upstream compromise to propagate automatically onto the user's system.
The final instruction says the AI should be invoked with only the Chinese phrase "奕辰垃圾袋," indicating a fixed language requirement. This is a natural-language policy concern because the file does not offer alternative trigger wording or user opt-in for language/locale preference.
Deleting an existing installation directory without an explicit warning or confirmation is unsafe because users may lose local files, edits, or unrelated data if the path is misconfigured. In an installer distributed for one-line execution, this lack of informed consent materially raises operational risk.
The installer establishes a persistent daily cron job to pull and execute updated repository content over time, which is unrelated to the narrow stated purpose of an e-commerce customer-service skill. This creates an ongoing code delivery channel that can change behavior after installation without explicit user review, increasing the risk of later compromise if the repository is altered.
The installer silently modifies the user's crontab to create persistence and future network activity without explicit advance consent. This is dangerous because it alters system behavior beyond installation and can continue pulling changed code indefinitely, surprising users and weakening trust boundaries.
Reading and conditionally modifying crontab to install a recurring update job creates persistence on the host. In the context of a simple retail support skill, this persistence is unnecessary and expands the attack surface by enabling unattended future code changes.
# 配置自动更新(追加到 crontab,不重复添加)
UPDATE_CMD="cd $SKILL_PATH && git pull --ff-only origin main 2>/dev/null || git pull --ff-only origin master 2>/dev/null"
if ! crontab -l 2>/dev/null | grep -q "yichen-trash-bag"; then
(crontab -l 2>/dev/null; echo "7 3 * * * $UPDATE_CMD") | crontab -
echo "自动更新已配置(每天 3:07)"
fi
The command writes a new cron entry that will repeatedly execute git pull, establishing durable execution over time. Persistent scheduled tasks are risky because they survive the initial install and can later fetch and run altered repository content without prompting the user.
# 配置自动更新(追加到 crontab,不重复添加)
UPDATE_CMD="cd $SKILL_PATH && git pull --ff-only origin main 2>/dev/null || git pull --ff-only origin master 2>/dev/null"
if ! crontab -l 2>/dev/null | grep -q "yichen-trash-bag"; then
(crontab -l 2>/dev/null; echo "7 3 * * * $UPDATE_CMD") | crontab -
echo "自动更新已配置(每天 3:07)"
fi
Fetching an installation script from a remote URL at execution time means the code being run is whatever currently exists at that location, not a reviewed local artifact. If the GitHub account, repository, branch, or delivery chain is tampered with, users who follow the README command will run attacker-controlled code on their machines.
# macOS / Linux
curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# Windows(PowerShell)
powershell -c "irm https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.ps1 | iex"
L029 明确要求该 Skill 仅做咨询,不得作出越权处理承诺;但 L239-L243 的话术要求包含“我帮您记录反馈给店铺”,这暗示 Skill 会代为记录或转交反馈。由于本文件整体仅声明读取 references/ 文件进行回复,并未体现任何记录或转交机制,这种文案会让 Skill 的实际能力与文档承诺产生矛盾。
The installer recommends fetching and executing a remote script directly from a raw URL, which bypasses normal review and integrity validation. This is risky because users are encouraged to trust whatever content is served at execution time, including any future repository changes or account compromise.
# 奕辰垃圾袋(Yichen Trash Bag)Skill · 一键安装脚本
# ============================================================
# 用法(客户只需运行这一行):
# curl -sSL https://raw.githubusercontent.com/Liubuq-sys/yichen-trash-bag-skill/main/install.sh | bash
# ============================================================
set -e
The script forcefully deletes an existing target directory when it is not a git checkout, which is a destructive system modification beyond simple skill installation. Although scoped to the skill path, it can cause data loss or overwrite local customizations without confirmation.
Line 56 instructs users to trigger the skill using the Chinese phrase “奕辰垃圾袋” only, which imposes a language-specific activation pattern. The file does not offer alternative language options or explain why the trigger must be limited to that locale.
The markdown content presents all product information exclusively in Chinese, which can constitute a language/locale policy violation under the stated rules when no user opt-in or justification is provided. There is no indication that this file is intentionally limited to a Chinese-speaking or region-specific audience.
No suspicious patterns detected.