T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:24- Finding
Unpinned Remote Package Installation Allows Payload Substitution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 24
Vulnerability Type: Unpinned installation of executable code from a remote repository
Risk Level: Highbash pip install git+https://github.com/lrg913427-dot/agent-lens.gitTechnical Analysis
The Quick Start instructions install a Python package directly from the default revision of a remote Git repository. The URL does not specify a reviewed commit hash, immutable release tag, package version, or integrity hash.
Consequently, the code executed by this command can change after the Skill has been audited. A Python package installation can invoke package build logic and installs modules that users are subsequently instructed to import and execute. Control of the repository, its default branch, or the associated GitHub account would therefore allow a substituted payload to execute during installation or later package use.
The audit did not establish that the current remote repository is malicious. The vulnerability is the mutable, unverified remote execution path and the resulting inability to bind installation to the reviewed content.
Attack Path
- An attacker compromises the repository owner account, gains write access to the repository, or otherwise causes malicious content to be served from its default branch.
- The attacker modifies package source code or installation/build configuration to contain a malicious payload.
- A user follows the documented Quick Start command.
pipretrieves the repository's current content rather than a revision fixed at audit time.- Malicious build hooks may execute during installation, or the installed payload executes when the documented
agent_lenspackage oragent-lenscommand is used. - The payload operates with the privileges and environmental access of the user running
pipor invoking the installed package.
Impact Assessment
Successful exploitation could provide arbitrary co ...[truncated 715 chars]
- Remediation
View remediation
Remediation Suggestions
- Publish the dependency through a controlled package registry and require an exact, reviewed version.
- Use hash-verified installation, such as a locked requirements file with
--require-hashes, so altered artifacts are rejected. - If installation from Git is unavoidable, pin the URL to a full reviewed commit SHA rather than a branch or mutable tag:
bash pip install "agent-lens @ git+https://github.com/lrg913427-dot/agent-lens.git@FULL_REVIEWED_COMMIT_SHA" - Record the expected commit identity and verify signed commits or release signatures where available.
- Review the pinned package source, including
pyproject.toml,setup.py, build backend configuration, console entry points, and imported runtime modules. - Perform installation in an isolated virtual environment without administrator privileges and with sensitive environment variables removed.
- Add automated dependency monitoring and require security review before updating the pinned revision.
