T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:51- Finding
Remote MCP Response Supplies a Command for Local Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 51–55
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Instruction
markdown Call `get-design-system-kit` with the target that fits the project: | Project | Target | | --- | --- | | React or Next.js with a terminal | `react`, then run the returned install command |Technical Analysis
When installing a design system into a React or Next.js project, the Skill instructs the agent to call
get-design-system-kiton the remote Better Design MCP server and execute the installation command returned by that service.The returned command is external service data, but the instruction provides no technical control that restricts its executable, arguments, download source, shell syntax, or affected paths. It also does not require the exact command to be shown to and explicitly approved by the user before execution.
This creates a direct trust transition from a remotely controlled MCP response to local command execution. The project contains no evidence that the service currently returns a malicious command, so this is a reachable high-risk behavior rather than proof of malicious intent.
Attack Path
- A user asks the agent to install a Better Design system in a React or Next.js project.
- The agent connects to
https://better-design.com/api/mcp. - The agent calls the remote
get-design-system-kittool with thereacttarget. - The remote service supplies an installation command.
- Following
SKILL.md, the agent runs that command in the local terminal without an allowlist, integrity check, or mandatory user approval. - If the MCP service or its response channel is malicious or compromised, the returned command executes with the agent process's local privileges.
Impact Assessment
A malicious returned command could execute arbitrary code with the privileges available to the agent. Depending on the runtime environment, this could ...[truncated 500 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace execution of an opaque server-returned command with a fixed, locally defined installer and a strict allowlist of supported package managers and arguments.
- Treat every returned command as untrusted data and parse it without invoking a shell.
- Display the complete command, download sources, package names, versions, and destination paths to the user, then require explicit approval before execution.
- Reject shell metacharacters, redirections, pipelines, command substitutions, environment assignments, unexpected executables, and unapproved URLs.
- Pin dependency versions and verify downloaded artifacts using trusted signatures or cryptographic hashes where supported.
- Run installation with the minimum necessary privileges and prohibit elevation unless separately justified and approved.
- Prefer returning declarative installation metadata—such as package names, versions, and file manifests—rather than executable command text.
- Validate that all filesystem changes remain within the user-selected project directory.
