T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:31- Finding
Unverified Remote Installer Piped Directly into a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:31, with the same instruction duplicated atREADME.md:37and printed byscripts/polymarket.py:49
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippets
SKILL.md:31:bash curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | shREADME.md:37:bash curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | shscripts/polymarket.py:49:python print(" Install: curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | sh", file=sys.stderr)Technical Analysis
The installation command downloads
install.shfrom the mutablemainbranch of an external GitHub repository and immediately passes the response tosh. The effective code executed on a user's system can therefore change after this Skill has been reviewed.The command provides no immutable commit pin, release-version pin, checksum validation, cryptographic signature verification, or local inspection step. The
-Loption also follows redirects, so the shell executes the final response body without confirming that it came from the originally displayed location.The URL belongs to the declared Polymarket project and installing its CLI is relevant to the Skill's trading features. However, immediate execution of mutable network content is not the minimum privilege or minimum-risk mechanism needed to install that dependency. The read-only features do not require the CLI at all, while trading users could install a pinned, verified release artifact instead.
The Python program does not itself execute this installation string; it prints the instruction when the CLI is missing. Nevertheless, both the Skill instructions and the program direct the user or agent toward the unsafe execution pattern.
Attack Path
- An attacker compromises the upstream repository, a main ...[truncated 1801 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every instruction that pipes a network response directly into a shell, including the copies in
SKILL.md,README.md, andscripts/polymarket.py. - Pin the dependency to a reviewed release version or immutable commit rather than the mutable
mainbranch. - Prefer an official package manager or a signed release artifact from the upstream publisher.
- Download the artifact to disk before execution so that its origin, contents, and expected filename can be reviewed.
- Publish and verify a SHA-256 checksum obtained through a trusted, independently protected channel.
- Verify a cryptographic signature where upstream signing is available.
- Fail closed on download errors by using
curl -f, and avoid executing responses that may be error pages or unexpected redirected content. - Keep installation separate from ordinary Skill execution and require explicit user approval.
- Document that read-only functionality does not require installation, limiting exposure to users who explicitly need trading features.
A safer installation pattern would resemble:
bash curl -fL \ -o polymarket-install.sh \ "https://raw.githubusercontent.com/Polymarket/polymarket-cli/<immutable-commit>/install.sh" echo "<trusted-sha256> polymarket-install.sh" | sha256sum -c - less polymarket-install.sh sh polymarket-install.shFor stronger hardening, replace the installer script with a pinned release binary and verify both its publisher signature and checksum before installation.
- Remove every instruction that pipes a network response directly into a shell, including the copies in
