T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:17- Finding
Unverified Remote Installation Script Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–21
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
markdown 1. **Install Claude Code CLI**: ```bash curl -fsSL https://claude.ai/install.sh | bash ```Technical Analysis
The installation instructions pipe content retrieved from an external URL directly into
bash. This makes the code that ultimately executes mutable after the Skill has been reviewed. No version is pinned, and no checksum, cryptographic signature, or trusted package metadata is verified before execution. The command also provides no opportunity to inspect the downloaded script separately.HTTPS protects the connection in transit but does not establish that every future version of the hosted script is safe. Compromise of the hosting account, deployment pipeline, DNS or delivery infrastructure could cause attacker-controlled shell commands to execute. While installing Claude Code is relevant to the declared functionality and the URL appears associated with the named service, immediate execution of unverified network content exceeds the minimum-risk installation process.
Attack Path
- An attacker compromises the remote script, its publishing pipeline, hosting infrastructure, or another component of its delivery path.
- A user follows the prerequisite command in
SKILL.md. curlretrieves the attacker-controlled content from the mutable remote endpoint.- The pipe sends the response directly to
bashwithout local review or integrity verification. - The malicious commands execute with all privileges available to the user running the installation command.
- The payload can access or alter resources available to that account, potentially including repositories, environment credentials, authentication material, shell configuration, and user-level startup mechanisms.
Impact Assessment
Succ ...[truncated 577 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the
curl | bashworkflow with an official package-manager installation method that verifies signed repository metadata and supports pinned versions. - If a standalone installer is required, download a version-specific artifact to disk without executing it immediately.
- Publish and verify a cryptographic signature from a trusted signing key. At minimum, verify a SHA-256 digest obtained through an independently authenticated channel.
- Present the downloaded script for inspection before execution and run it as a separate, explicit command.
- Avoid
sudoor administrator execution unless a documented installation step strictly requires it. Prefer a user-scoped installation directory with minimal filesystem permissions. - Pin the installer or release version rather than relying on a mutable endpoint such as
install.sh. - Document the files, network access, and configuration changes the installer is expected to make so users can validate its behavior.
A safer conceptual workflow is:
bash curl -fSLo claude-installer.sh "https://trusted.example/claude/<pinned-version>/install.sh" echo "<trusted-sha256> claude-installer.sh" | sha256sum --check - less claude-installer.sh bash claude-installer.shThe actual download URL, digest, and signature-verification procedure must come from authenticated official release documentation.
- Replace the
