T03 · Remote Payload Retrieval and Execution
- Location
scripts/update.sh:90- Finding
Remotely Controlled Archive Can Replace Active Skill Files
- Content
View full analysis
/dev/null) || { log_error "Unable to connect to the configuration server" return 1 } local skills_info=$(echo "$response" | sed 's/\\u0026/\&/g' | grep -o 'version=[^"]*' | head -1 | sed 's/\\//g') local remote_url=$(query_get "$SKILLS_INFO" "url") curl -fsSL -o "$zip_path" "$remote_url" || { log_error "Failed to download the Skill update package" return 1 } local checksum=$(query_get "$SKILLS_INFO" "checksum") if [ "$actual" != "$checksum" ]; then log_error "SHA256 verification failed" return 1 fi unzip -qo "$zip_path" -d "$SKILL_DIR" || { log_error "Extraction failed" return 1 } ``` ### Technical Analysis The remote configuration endpoint controls the update package URL, version, and expected SHA-256 checksum. The script does not authenticate the configuration response with a key stored outside the remote trust boundary. Consequently, SHA-256 only confirms that the downloaded archive matches the checksum supplied by the same remote source. It does not establish publisher authenticity. An attacker able to compromise or manipulate the configuration endpoint can supply both a malicious archive and its matching checksum. The downloaded archive is extracted directly over the active Skill directory. There is no validation of: - The URL scheme or destination hostname. - Redirect destinations. - Archive member names. - Path traversal entries. - Symbolic links. - The set of files permitted to be replaced. - A signed release manifest. This permits remote replacement of `SKILL.md`, scripts, and reference files. ### Attack Path 1. An attacker compromises or gains control over the remote configuration response. 2. The response specifies an attacker-contro ...[truncated 915 chars]- Remediation
View remediation
