T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:16- Finding
Execution of Mutable Remote Code and Unverified Downloaded Binaries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16-18,SKILL.md:23-27,HEARTBEAT.md:5-8, andHEARTBEAT.md:15-18
Vulnerability Type: Remote payload retrieval and insecure software supply chain
Risk Level: HighEvidence
SKILL.md:16-18instructs the user or agent to clone a mutable repository without pinning a commit or verifying its integrity:bash ## Installation ```bash git clone https://github.com/mrbeandev/workspace-explorer.gittext `SKILL.md:23-27` then instructs execution of a script obtained from that repository. The documentation states that the script downloads additional binaries: ```bash Run the start script with the workspace path: ```bash python3 {baseDir}/scripts/start_workspace.py /path/to/workspaceThe script will:
- Download binaries on first run (code-server + cloudflared)
text `HEARTBEAT.md:5-8` requests periodic execution of the same externally obtained script: ```markdown ## Checklist 1. **Check Status**: Run `python3 {baseDir}/scripts/start_workspace.py --status`. 2. **Monitor Activity**: If a workspace is active:HEARTBEAT.md:15-18repeats that command:bash ## Commands ```bash # Check if services are running python3 {baseDir}/scripts/start_workspace.py --statustext ### Technical Analysis The audited package contains only `SKILL.md` and `HEARTBEAT.md`; the referenced `scripts/start_workspace.py` implementation is not included. Instead, installation points to the current state of a personal GitHub repository with no immutable commit hash, signed release, checksum, or other integrity constraint. Consequently, the code that is eventually executed can differ from the content available when this skill package was reviewed. If the repository, its maintainer account, release infrastructure, or referenced download locations are compromised, an attacker can alter `start_workspace.py` or the binaries it retrie ...[truncated 2919 chars]- Remediation
View remediation
Remediation Suggestions
- Include the complete
scripts/start_workspace.pyimplementation and supporting code in the reviewed skill package rather than requiring a mutable repository clone. - If remote retrieval is unavoidable, pin the repository to a full immutable commit hash and verify that hash before execution. Prefer signed, versioned releases from a controlled organization.
- Pin exact versions of
code-serverandcloudflared. Publish expected SHA-256 or stronger hashes and verify each artifact before making it executable. - Verify vendor signatures where available and fail closed if signature or checksum validation fails.
- Restrict downloads to HTTPS URLs on explicitly approved vendor domains. Do not follow unexpected redirects or select artifacts from untrusted mirrors.
- Vendor minimal required dependencies where licensing permits, and generate a software bill of materials documenting every downloaded component and version.
- Review status behavior and ensure
--statusperforms no installation, downloading, tunnel creation, or other state-changing activity. Consider implementing status checking through a small bundled, read-only utility. - Run the workspace service as a dedicated unprivileged account with access only to the explicitly selected workspace. Deny access to SSH keys, cloud credentials, unrelated home-directory files, and sensitive environment variables.
- Bind code-server only to localhost, require strong authentication, limit tunnel lifetime, and display an explicit confirmation before creating any public tunnel.
- Document all outbound connections, downloaded artifact sources, storage paths, and cleanup behavior so reviewers can verify the complete trust chain.
- Include the complete
