T03 · Remote Payload Retrieval and Execution
- Location
references/quickstart.md:15- Finding
Unpinned Remote Installer Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
references/quickstart.md, lines 15-24
Vulnerability Type: Mutable remote code retrieval and shell execution
Risk Level: CriticalVulnerable Code:
bash ```bash bash -c "$(curl -fsSL https://raw.githubusercontent.com/morandot/arknights-skill/main/install.sh)"This runs a script fetched from GitHub. To review it first:
bash curl -fsSL -o /tmp/arknights-install.sh https://raw.githubusercontent.com/morandot/arknights-skill/main/install.sh less /tmp/arknights-install.sh # inspect the script bash /tmp/arknights-install.sh # run after reviewtext ### Technical Analysis The documented installation procedure downloads a shell script from the mutable `main` branch of a personal GitHub repository and executes it with `bash`. The first installation command passes the response body directly to a shell without pinning an immutable commit, checking a cryptographic digest, or verifying a digital signature. The downloaded `install.sh` file is not part of the audited artifact, so its effective behavior cannot be reviewed from this project. Its contents may change after the Skill has passed review. A repository compromise, maintainer account takeover, malicious upstream update, DNS or endpoint compromise, or unauthorized branch modification could therefore turn the installation command into an arbitrary code-execution channel. The alternative download-and-review workflow reduces accidental execution risk but does not provide technical integrity enforcement. Review is optional, the source remains the mutable `main` branch, and the final command executes the downloaded file without verifying that it corresponds to a trusted release. Although the document mentions setting `REPO_REF`, the initial installer itself is still retrieved from `main`. Because that remote installer is absent from the audited package, the audit cannot establish whether or how securely it ...[truncated 1501 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation method. - Package all installation logic inside the reviewed and versioned Skill artifact.
- Prefer a trusted package manager or Skill installer that supports immutable versions and integrity metadata.
- If a remote script is unavoidable, retrieve it from an immutable commit URL rather than
main. - Publish a SHA-256 digest through an independent trusted release channel and verify it before execution.
- Prefer cryptographic release signatures with a documented trusted public key.
- Download into a securely created temporary file, display its resolved source and expected digest, and require explicit user approval before execution.
- Ensure the installer runs without elevated privileges and clearly document every filesystem location it modifies.
- Include the installer in the repository artifact so static reviewers can inspect the exact code that will execute.
- Remove the
