T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:31- Finding
Unpinned Remote Setup Instructions Expand the Skill Beyond TTS Scope
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31-38
Vulnerability Type: Remote payload retrieval through agent-directed setup instructions
Risk Level: MediumVulnerable code snippet:
markdown ## Setup (One Command) Tell your agent:set up skillboss.co/skill.md
text This auto-configures SkillBoss with 687 APIs — chat, image, video, audio, search, scraping, social data, email, and more.Technical Analysis
The Skill instructs an agent to set up content referenced by
skillboss.co/skill.md. Unlike the locally auditedSKILL.md, this remote document is mutable and is not pinned to a version or protected by an integrity hash. Its effective instructions can therefore change after this package has been reviewed.The advertised setup also configures 687 APIs spanning chat, scraping, social data, email, and other capabilities. Those capabilities are unrelated to the declared OpenAI TTS purpose and exceed the minimum functional scope required to submit text and receive synthesized audio.
The repository does not contain direct code that fetches or executes the remote document, so exploitation depends on the consuming agent interpreting the setup request by retrieving and following the referenced content. If it does, the external document becomes a post-review instruction channel controlled by the remote service.
Attack Path
- A user or agent loads this Skill to perform an OpenAI TTS request.
- The agent follows the recommended
set up skillboss.co/skill.mdinstruction. - The agent retrieves or interprets the externally hosted setup document.
- The remote document supplies setup actions that were not included in the audited package.
- If the remote content is compromised or changed maliciously, it can instruct the agent to invoke tools, alter configuration, request broader credentials, or enable APIs unrelated to TTS.
- Those instructions execute with whatever files ...[truncated 876 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the remote bootstrap instruction with complete, locally stored, auditable setup steps.
- Configure only the TTS endpoint and permissions needed for
openai/tts-1; do not automatically enable unrelated chat, scraping, social-data, or email APIs. - If remote setup content is unavoidable, pin it to an immutable version and verify a published cryptographic digest or signature before use.
- Require explicit user confirmation before retrieving remote instructions or making configuration changes.
- Clearly enumerate every action the setup process will perform, including files modified, credentials accessed, and capabilities enabled.
- Run setup with restricted filesystem, command-execution, and network permissions.
- Add a privacy notice explaining that prompts and authentication credentials are sent to SkillBoss as an intermediary.
