T03 · Remote Payload Retrieval and Execution
- Location
install.sh:3- Finding
Mutable Remote Installer and Unpinned Supply Chain
- Content
View full analysis
/install.sh | bash set -e SKILL_DIR="${HOME}/.claude/skills/halo-skill" REPO_URL="${1:-https://github.com/lululu811/halo-skill.git}" ``` ```bash if [ -d "${SKILL_DIR}" ]; then echo "Updating existing installation..." cd "${SKILL_DIR}" git pull else echo "Cloning into ${SKILL_DIR}..." git clone "${REPO_URL}" "${SKILL_DIR}" fi ``` ```bash source .venv/bin/activate echo "Installing dependencies..." pip install -q requests ``` ### Technical Analysis The installer advertises piping a remotely downloaded script directly into Bash. This executes the response before the user can inspect it and makes the effective payload depend on mutable remote content rather than the audited package. The subsequent installation process compounds that risk: - `REPO_URL` can be supplied by the caller and is not restricted to an approved repository. - `git clone` installs the current state of the remote default branch without pinning a commit or signed release. - `git pull` automatically incorporates new remote code into an existing Skill installation. - `pip install -q requests` installs an unpinned package without hash verification. - The resulting Skill is placed under `~/.claude/skills`, where it may be loaded in future Agent sessions. The repository URL currently defaults to the project’s stated GitHub repository, and no malicious embedded payload was found in the audited snapshot. Nevertheless, the installation method permits the executed and installed code to change after review. ### Attack Path 1. An attacker compromises the installer hosting location, repository, maintainer account, release process, DNS/TLS trust path, or dependency public ...[truncated 1228 chars]- Remediation
View remediation
