Back to skill

Security audit

Environment & Package Manager

Security checks for vulnerabilities and agentic risk

Overview

This package-management skill is transparent about its purpose, but it should be reviewed because it includes a high-risk auto-install command that runs a remote script directly in the shell.

Prefer the Homebrew install path or a reviewed manual installer. Do not let an agent run the `curl | sh` auto-install command unless the environment is disposable, contains no secrets, and you explicitly accept that the remote server controls code executed as your user. Confirm before running cleanup, removal, or upgrade-all commands because they can change installed tools.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
data/install.md:25
Finding

Remote Installer Command Executes Mutable Network Content Without Prior Verification

Content
View full analysis

Vulnerability Details

File Location: data/install.md, line 25
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

yaml
command: "curl -fsSL https://get.x-cmd.com | sh"

Technical Analysis

The installation metadata defines a command that retrieves content from https://get.x-cmd.com and passes it directly to sh. The payload is neither pinned to an immutable version nor authenticated with a known checksum or signature before execution.

HTTPS protects the connection to the currently authenticated endpoint, but it does not guarantee that the returned installer remains identical to the version reviewed during this audit. If the domain, hosting infrastructure, served installer, DNS resolution, or TLS trust chain is compromised, arbitrary commands can be supplied and executed immediately.

The document claims that downloaded binaries receive SHA-256 verification, but it also acknowledges that this verification occurs after the initial installer has begun executing. Consequently, it cannot establish the integrity of the bootstrap script itself.

This behavior exceeds the minimum privileges and capabilities needed to document or install the package manager. The project already provides lower-risk alternatives, including Homebrew installation and downloading the installer for review before execution.

Attack Path

  1. A user or agent selects the automatic installation method.
  2. curl requests the current payload from get.x-cmd.com.
  3. An attacker compromises or impersonates an element of the remote delivery chain, or modifies the installer hosted at the endpoint.
  4. The attacker-controlled response is streamed directly into sh.
  5. The shell executes the response before any meaningful integrity validation of the bootstrap script.
  6. The payload can inspect or modify resources available to the invoking user and retrieve additional unreview ...[truncated 780 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the direct curl | sh command from the installation metadata.
  2. Replace it with a versioned, immutable installer artifact.
  3. Publish a cryptographic signature or trusted SHA-256 digest through an independent, authenticated channel.
  4. Download the installer into a safely created temporary file and verify its signature or checksum before invoking a shell.
  5. Require explicit user approval after verification and, where practical, after source review.
  6. Prefer a reputable package manager with reviewed and versioned package metadata.
  7. Ensure agents never execute mutable remote scripts automatically, including in disposable environments.

T03 · Remote Payload Retrieval and Execution

Error
Location
data/install.md:104
Finding

User-Facing Auto-Install Instructions Pipe an Unpinned Remote Script Into a Shell

Content
View full analysis

Vulnerability Details

File Location: data/install.md, line 104
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Critical

Complete Code Snippet:

bash
curl -fsSL https://get.x-cmd.com | sh

Technical Analysis

The user-facing installation guide presents a command that immediately executes a mutable remote response. There is no opportunity to inspect the retrieved content, no version pinning, and no signature or checksum validation before shell interpretation.

The surrounding documentation appropriately labels this option as high risk, restricts it to disposable environments, and states that explicit consent is required. These warnings reduce the likelihood of accidental use but do not mitigate the technical vulnerability in the command itself. Once invoked, the remote server controls the commands interpreted by the local shell.

This execution channel is unnecessary for the Skill's declared package-management functionality because the guide already documents Homebrew and download-review-execute alternatives.

Attack Path

  1. The user or agent follows the documented auto-install command.
  2. The endpoint returns an installer that differs from the previously reviewed version, whether through a legitimate update or malicious compromise.
  3. curl streams that response directly to the shell.
  4. sh interprets and executes each received command with the invoking user's permissions.
  5. A malicious installer can modify user files, tamper with the shell environment, obtain accessible secrets, or fetch subsequent payloads.
  6. Any checksum checks performed later by the installer cannot reverse or prevent commands already executed by the bootstrap stage.

Impact Assessment

Successful exploitation provides arbitrary command execution within the invoking user's security context. The reachable scope includes user-owned files, environment variables, accessible authentication ...[truncated 511 chars]

Remediation
View remediation

Remediation Suggestions

  1. Delete the curl -fsSL ... | sh example rather than relying solely on warning text.
  2. Make Homebrew or another reviewed package-manager route the primary installation method.
  3. For manual installation, download a version-specific artifact without executing it.
  4. Verify the artifact against a pinned signature or digest before execution.
  5. Store temporary installer files with restrictive permissions and avoid predictable filenames where possible.
  6. Present the verified script for review and require explicit confirmation before executing it.
  7. Update agent guidance to prohibit direct network-to-shell pipelines in all environments.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

External Script Fetching

High
Category
Supply Chain
Confidence
98% confidence
Finding

The documented command pipes a remotely fetched script directly into a shell, which enables immediate arbitrary code execution from a network source. Even though the document labels this method high-risk, including it as an installation option still exposes users and agents to supply-chain compromise if the domain or transport path is compromised.

Content

Scanner excerpt · data/install.md (reported line 25)May include surrounding context.

md
recommendation: "acceptable with review"
      requires_review: true
    - name: install-script-auto
      command: "curl -fsSL https://get.x-cmd.com | sh"
      verification: checksum
      risk_level: high
      recommendation: "avoid in sensitive environments"

External Script Fetching

High
Category
Supply Chain
Confidence
90% confidence
Finding

Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.

Content

Scanner excerpt · data/install.md (reported line 81)May include surrounding context.

bash
# 1. Download install script
curl -fsSL https://get.x-cmd.com > /tmp/x-cmd-install.sh

# 2. REVIEW the script content (critical step)
cat /tmp/x-cmd-install.sh

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

Shell chaining via | sh executes remote content immediately without inspection, making any compromise of the remote endpoint equivalent to arbitrary command execution on the host. In an agent skill context this is more dangerous because the skill may normalize unsafe automation of installation steps.

Content

Scanner excerpt · data/install.md (reported line 104)May include surrounding context.

⚠️ WARNING: This executes remote code without manual review.

bash
curl -fsSL https://get.x-cmd.com | sh

Only use when:

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · data/install.md (reported line 181)May include surrounding context.

x-cmd is entirely contained in ~/.x-cmd.root/. To remove:

bash
rm -rf ~/.x-cmd.root/
# Also remove from shell config (~/.bashrc, ~/.zshrc):
# [ ! -f "$HOME/.x-cmd.root/X" ] || . "$HOME/.x-cmd.root/X"

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · data/install.md (reported line 181)May include surrounding context.

x-cmd is entirely contained in ~/.x-cmd.root/. To remove:

bash
rm -rf ~/.x-cmd.root/
# Also remove from shell config (~/.bashrc, ~/.zshrc):
# [ ! -f "$HOME/.x-cmd.root/X" ] || . "$HOME/.x-cmd.root/X"

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · data/install.md (reported line 95)May include surrounding context.

md
1. Creates `~/.x-cmd.root/` directory (user-local)
2. Downloads x-cmd core files from GitHub releases
3. Verifies SHA256 checksums of all downloaded files
4. No system modifications, no sudo required

---

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

The skill documents package removal and cleanup commands such as unuse and gc without explicitly warning that they modify the user's environment and may delete installed software or dependencies. In a package-management skill this behavior is expected, but the lack of safety guidance can still lead to accidental destructive actions, especially if an agent executes commands on behalf of a user without confirming intent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The examples include bulk upgrade operations like x env use --upgrade --all and x env upgrade --all without warning that they can change multiple installed tool versions across the user's environment. In context this is normal package-manager functionality, but absent cautions about version drift or compatibility breakage, an agent or user could trigger widespread unexpected changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.