T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:151- Finding
Unverified Remote Setup Script Is Piped Directly into Bash
- Content
View full analysis
" \ "https://raw.githubusercontent.com//wb-sync/main/wb-setup-machine.sh" | bash ``` ### Technical Analysis The documented installation procedure downloads a shell script from a mutable GitHub branch and pipes the response directly into Bash. The downloaded content is not pinned to an immutable commit and is not verified using a cryptographic hash or signature. Transport encryption and the authorization header only protect transport and repository access. They do not protect users if the repository, maintainer account, token, branch, or hosted script is compromised. The user also has no opportunity to inspect the exact payload before execution. Because the URL references `main`, the effective code executed by this command can change after the Skill itself has been reviewed. ### Attack Path 1. An attacker compromises the GitHub repository, a maintainer account, or a token with repository write access. 2. The attacker modifies `wb-setup-machine.sh` on the `main` branch to include a malicious payload. 3. A user follows the installation instructions in `SKILL.md`. 4. `curl` retrieves the attacker-controlled version of the script. 5. Bash executes the response immediately with the permissions of the current user. 6. The payload can access user files, alter shell configuration, steal locally available credentials, or install additional persistence. ### Impact Assessment Successful exploitation provides arbitrary code execution under the account running the command. This normally includes access to the user's WorkBuddy configuration, synchronized data, Git credentials, shell startup files, and any other resources accessible to that user. The impact extends to every machine on which a user follows the docume ...[truncated 175 chars]- Remediation
View remediation
/wb-sync//wb-setup-machine.sh" printf '%s %s\n' '' 'wb-setup-machine.sh' | shasum -a 256 -c - less wb-setup-machine.sh bash wb-setup-machine.sh ``` ]]>
