T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:79- Finding
Unpinned Remote Installer Is Piped Directly to a Shell
- Content
View full analysis
= 1.0 ### Install Bun ```bash curl -fsSL https://bun.sh/install | bash ``` ``` ### Technical Analysis The installation instructions download a mutable script from an external URL and immediately execute it with Bash. The downloaded content is not displayed for review, pinned to a version, checked against a cryptographic digest, or verified using a signature. Although `bun.sh` is the documented Bun project domain, this pattern transfers control of the effective installation payload to external infrastructure after the Skill has been reviewed. Compromise of the upstream server, its deployment process, DNS resolution, or a trusted delivery component could cause arbitrary replacement code to be executed. Installing Bun is necessary for the declared functionality, but executing an unverified network response directly is not the minimum privilege or minimum-risk method required to install it. ### Attack Path 1. An attacker compromises or gains the ability to modify the script returned by `https://bun.sh/install`. 2. A user follows the Skill documentation and runs the provided command. 3. `curl` downloads the attacker-controlled response. 4. The shell pipeline passes that response directly to Bash without verification or inspection. 5. Bash executes the payload with all permissions available to the user who launched the command. 6. The payload can access or modify any files, credentials, processes, or configuration available to that user. ### Impact Assessment Successful exploitation provides arbitrary command execution under the installing user's account. If the user runs the command with elevated privileges or from a privileged environment, the payload inherits that broader scope. Potential consequences include cre ...[truncated 303 chars]- Remediation
View remediation
