T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Mutable Remote Installer Is Downloaded and Executed as Root
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent for managing Inner Warden, but it needs review because it recommends root-level installation and repair actions, including a mutable GitHub installer run with sudo.
Install only if you are comfortable giving the skill host-administration authority for Inner Warden. Review the installer source and prefer a pinned, signed release or package-manager install before running anything with sudo; also verify exact remediation commands before approving service restarts, ACL changes, config edits, or log compression.
SKILL.md:30Mutable Remote Installer Is Downloaded and Executed as Root
SKILL.md:57Unauthenticated Local API Is Trusted as the Final Safety Authority for Privileged Commands
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
ALWAYS run this first:
which innerwarden 2>/dev/null && sudo innerwarden status 2>/dev/null || echo "NOT_INSTALLED"
If NOT_INSTALLED, tell the user:
The skill instructs downloading and then executing a remote install script with sudo from GitHub. Even with manual inspection and checksum discussion for later binaries, this pattern creates a high-risk remote code execution path because the script itself is not pinned to a specific version or cryptographically verified before privileged execution.
To install, first download and inspect the install script:
curl -fsSL https://github.com/InnerWarden/innerwarden/releases/latest/download/install.sh -o /tmp/innerwarden-install.sh
less /tmp/innerwarden-install.sh
Running 'sudo bash /tmp/innerwarden-install.sh' executes a downloaded script with full root privileges. If the script source, transport, GitHub account, release pipeline, or local temporary file is compromised, this grants immediate complete system compromise.
Then run it:
sudo bash /tmp/innerwarden-install.sh
The install script downloads binaries from GitHub Releases and verifies each
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Auth required. The dashboard user is in /etc/innerwarden/agent.env (key
# INNERWARDEN_DASHBOARD_USER); the password is NOT stored (argon2 hash only).
# Optionally set INNERWARDEN_DASHBOARD_USER in the environment to skip the lookup.
USER_HINT="${INNERWARDEN_DASHBOARD_USER:-$(sudo grep -oP '^INNERWARDEN_DASHBOARD_USER=\K.*' /etc/innerwarden/agent.env 2>/dev/null)}"
echo "Dashboard auth is enabled (user: ${USER_HINT:-unknown})."
echo "Ask the user for the dashboard password, or disable auth: sudo innerwarden configure dashboard --no-auth"
fi
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Auth required. The dashboard user is in /etc/innerwarden/agent.env (key
# INNERWARDEN_DASHBOARD_USER); the password is NOT stored (argon2 hash only).
# Optionally set INNERWARDEN_DASHBOARD_USER in the environment to skip the lookup.
USER_HINT="${INNERWARDEN_DASHBOARD_USER:-$(sudo grep -oP '^INNERWARDEN_DASHBOARD_USER=\K.*' /etc/innerwarden/agent.env 2>/dev/null)}"
echo "Dashboard auth is enabled (user: ${USER_HINT:-unknown})."
echo "Ask the user for the dashboard password, or disable auth: sudo innerwarden configure dashboard --no-auth"
fi
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Auth required. The dashboard user is in /etc/innerwarden/agent.env (key
# INNERWARDEN_DASHBOARD_USER); the password is NOT stored (argon2 hash only).
# Optionally set INNERWARDEN_DASHBOARD_USER in the environment to skip the lookup.
USER_HINT="${INNERWARDEN_DASHBOARD_USER:-$(sudo grep -oP '^INNERWARDEN_DASHBOARD_USER=\K.*' /etc/innerwarden/agent.env 2>/dev/null)}"
echo "Dashboard auth is enabled (user: ${USER_HINT:-unknown})."
echo "Ask the user for the dashboard password, or disable auth: sudo innerwarden configure dashboard --no-auth"
fi
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Auth required. The dashboard user is in /etc/innerwarden/agent.env (key
# INNERWARDEN_DASHBOARD_USER); the password is NOT stored (argon2 hash only).
# Optionally set INNERWARDEN_DASHBOARD_USER in the environment to skip the lookup.
USER_HINT="${INNERWARDEN_DASHBOARD_USER:-$(sudo grep -oP '^INNERWARDEN_DASHBOARD_USER=\K.*' /etc/innerwarden/agent.env 2>/dev/null)}"
echo "Dashboard auth is enabled (user: ${USER_HINT:-unknown})."
echo "Ask the user for the dashboard password, or disable auth: sudo innerwarden configure dashboard --no-auth"
fi
The text says the skill 'NEVER transmits credentials off-host' and emphasizes localhost-only API calls, creating a strong impression of strictly local-only operations. Earlier instructions direct use of curl to GitHub to fetch an installer, which contradicts that local-only framing in the documentation even if credentials themselves are not sent.
The ACL remediation uses a placeholder path and grants access with sudo based on a generic 'permission denied' diagnosis. If an agent or user substitutes an attacker-influenced or unsafe path, this can broaden file access to the service account and expose sensitive logs or files beyond the intended scope.
sudo setfacl -m u:innerwarden:rx /path/to/log/file
sudo systemctl restart innerwarden-sensor
The bulk gzip command performs a recursive privileged modification across application data files older than seven days. Without safeguards, it can alter files currently relied on by the service, affect forensic retention, or follow unsafe assumptions about file types and state, causing data loss or service issues.
sudo du -sh /var/lib/innerwarden/
sudo find /var/lib/innerwarden/ -name "*.jsonl" -mtime +7 -exec gzip {} \;
The trigger condition "check everything" or "health check" is described in natural language without scope limits or negative examples. These phrases are broad enough to match common conversational requests and could cause the skill to run a full diagnostic workflow when the user intended something narrower.
The manifest describes a security partner that validates commands, monitors server health, and diagnoses or fixes issues in Inner Warden. Reading /etc/innerwarden/agent.env to extract INNERWARDEN_DASHBOARD_USER is not obviously necessary for those core functions, especially since the file contains authentication-related configuration and the skill already notes most functionality works without API auth.
No suspicious patterns detected.