T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:15- Finding
Unverified Mutable Third-Party Binaries Are Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15-40
Vulnerability Type: Remote retrieval and execution of unverified binaries
Risk Level: HighVulnerable Code
bash curl -L -o ~/Downloads/xhs-mcp.tar.gz \ "https://github.com/xpzouying/xiaohongshu-mcp/releases/latest/download/xiaohongshu-mcp-darwin-amd64.tar.gz" cd ~/Downloads && tar -xzf xhs-mcp.tar.gz mkdir -p ~/.local/bin mv xiaohongshu-login xiaohongshu-mcp ~/.local/bin/ chmod +x ~/.local/bin/xiaohongshu-* ~/.local/bin/xiaohongshu-login -bin "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" ~/.local/bin/xiaohongshu-mcp -bin "/Applications/Google Chrome.app/Contents/MacOS/Google Chrome" -port ":18060"Technical Analysis
The installation procedure retrieves precompiled executables from a mutable GitHub
latestrelease and then grants and invokes executable permissions. It does not pin a release version or commit, verify a cryptographic checksum, validate a digital signature, establish artifact provenance, or inspect archive entries before extraction.Consequently, the effective code executed by users can change after the Skill itself has been reviewed. Although the hosting platform is GitHub, the asset comes from a third-party personal repository and remains outside the audited project. TLS protects the transfer channel but does not establish that the publisher or release artifact is trustworthy.
The login executable is especially sensitive because it launches a browser for account authorization and creates a persistent authenticated session. A compromised executable would run with the installing user's privileges and could access the resulting cookies as well as other files available to that user.
Attack Path
- An attacker compromises the third-party repository, its maintainer account, release workflow, or release artifact.
- The attacker replaces the asset targeted by the mutable `releases/ ...[truncated 914 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latestURL with an immutable, explicitly reviewed release version. - Publish a trusted SHA-256 or stronger digest and require verification before extraction.
- Prefer signed releases and verify the signature against a documented maintainer key.
- Use provenance verification, such as Sigstore attestations, where available.
- Validate archive entries before extraction to reject absolute paths, traversal entries, links, and unexpected files.
- Avoid broad glob-based permission changes; verify exact filenames and grant execution permission only to those files.
- Prefer reproducible builds from pinned, reviewed source over opaque precompiled binaries.
- Clearly document that the downloaded executable is outside the Skill's audit boundary.
- Execute the component under a dedicated, restricted account or sandbox with minimal filesystem and network access.
- Replace the mutable
