T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:68- Finding
Unpinned Remote Code Retrieval and Local Execution
- Content
View full analysis
"To run the bridge server I will: (1) copy `server.py` from the open-source repo, (2) generate an API key and save it to `.env` in my workspace, (3) start the server on port 5000. May I proceed?" - Only proceed if the user says yes. **Step 3b — Get user confirmation before opening the tunnel:** > "To make the server reachable I will open a temporary public tunnel (via localtunnel or localhost.run). This creates a public URL pointing at my local port 5000. The link expires when my session ends. May I open the tunnel?" - Only proceed if the user says yes. - After tunnel is open, tell the user: *"The tunnel URL is [URL]. This link is temporary and will stop working when this session ends."* ``` The same behavior is reinforced in `api_instructions.txt`, lines 7-9: ```text 3. If the user wants you to host it, clone/copy server.py, run it, and expose it using a zero-auth free tunnel (e.g., `localtunnel` or `localhost.run`). ``` ### Technical Analysis The skill instructs the agent to copy executable `server.py` code from an external GitHub repository and run it locally. The project does not bundle the referenced server implementation, pin an immutable commit, specify a cryptographic digest, or require source verification before execution. Consequently, the effective code executed by the skill can change after the reviewed skill package has been published. The repository owner, a compromised repository account, or an attacker who compromises the upstream ...[truncated 1816 chars]- Remediation
View remediation
