T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:47- Finding
Mutable Remote Installer Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 47-49
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
sh curl -sSL https://raw.githubusercontent.com/agent-life/agent-life-adapters/main/scripts/install.sh -o install-alf.sh cat install-alf.sh # inspect the script sh install-alf.sh # run itTechnical Analysis
The Skill instructs users to retrieve an installer from the mutable
mainbranch of an external GitHub repository and execute it withsh. The effective installer payload can therefore change after this Skill has been reviewed or published.Displaying the script with
catdoes not provide cryptographic authentication and does not ensure that a user or agent will identify malicious changes. AlthoughALF_VERSIONcan reportedly pin the binary release selected by the installer, it does not pin or authenticate the installer itself.Neither the installer nor the executable implementation is included in the audited project. Consequently, the audit cannot independently verify the installer's filesystem operations, downloaded artifact selection, checksum implementation, or the CLI's stated data-handling guarantees.
Attack Path
- An attacker compromises the upstream repository, maintainer account, release process, or another component capable of changing content served from the referenced
mainbranch. - The attacker modifies
scripts/install.shto execute additional commands or install a substituted executable. - A user or agent follows the Skill instructions and downloads the current mutable script.
- The user executes it using
sh install-alf.sh. - The modified installer executes with the invoking user's permissions and can access data or modify files available to that user.
Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the account running the installer. ...[truncated 529 chars]
- An attacker compromises the upstream repository, maintainer account, release process, or another component capable of changing content served from the referenced
- Remediation
View remediation
Remediation Suggestions
- Do not retrieve an executable installer from a mutable branch.
- Vendor the reviewed installer in the Skill package, or fetch it using an immutable commit identifier.
- Publish an installer digest through a separately trusted channel and verify it before execution.
- Require cryptographic signatures for release binaries rather than relying solely on checksums hosted alongside those binaries.
- Pin a specific release by default instead of using
latestor a mutable branch. - Avoid privileged or system-wide installation by default; install into a dedicated user-controlled directory with minimal permissions.
- Include the installer and relevant CLI source in the review scope so their filesystem, network, encryption, and credential-handling behavior can be audited.
