T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:17- Finding
Dynamic Remote Installer Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 17–49
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighThe Skill requires an Agent to dynamically resolve the latest release, download an installer from GitHub, verify it against a checksum controlled by the same upstream repository, and execute it with the Agent user's permissions.
Vulnerable Code
markdown Every time before running any `onchainos` command, always follow these steps in order. Do not echo routine command output to the user; only provide a brief status update when installing, updating, or handling a failure. 1. **Resolve latest stable version**: Fetch the latest stable release tag from the GitHub API: ``` curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest" ``` Extract the `tag_name` field (e.g., `v1.0.5`) into `LATEST_TAG`. If the API call fails and `onchainos` is already installed locally, skip steps 2-3 and continue with step 4 (the user may be offline or rate-limited; a stale binary is better than blocking). If `onchainos` is **not** installed, **stop** and tell the user to check their network connection or install manually from https://github.com/okx/onchainos-skills. 2. **Install or update**: If `onchainos` is not found, or if the cache at `~/.onchainos/last_check` (`$env:USERPROFILE\.onchainos\last_check` on Windows) is older than 12 hours: - Download the installer and its checksum file from the latest release tag: - **macOS/Linux**: `curl -sSL "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/install.sh" -o /tmp/onchainos-install.sh` `curl -sSL "https://github.com/okx/onchainos-skills/releases/download/${LATEST_TAG}/installer-checksums.txt" -o /tmp/installer-checksums.txt` - **Windows**: `Invoke-WebRequest -Uri "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/i ...[truncated 4732 chars]- Remediation
View remediation
Remediation Suggestions
- Remove automatic installer execution from routine Skill use. Treat installation and updates as separate, explicit administrative operations.
- Require informed user approval before downloading or executing any installer, and display the exact source, version, destination, and command.
- Pin an audited immutable version rather than dynamically using
releases/latest. Prefer a release tied to an immutable commit identifier. - Use an independent authenticity mechanism. Verify release artifacts with a trusted signing key, Sigstore identity, or another signature whose trust root is not stored alongside the downloadable artifact.
- Bundle reviewed components where feasible. Include the required script or a reproducibly built binary in the reviewed package so the executed payload matches the audited content.
- Separate installer and checksum trust boundaries. A checksum published by the same potentially compromised release process should not be the only authenticity control.
- Apply least privilege. Execute installation in a restricted environment without administrative privileges, unnecessary credentials, wallet secrets, or broad filesystem access.
- Constrain downloaded installer behavior. Review it before execution, restrict allowed download destinations, and prohibit modification of unrelated startup files, services, or system tools.
- Use secure temporary-file handling. Create uniquely named files with restrictive permissions, avoid predictable shared
/tmppaths, reject symbolic links, and delete artifacts after verification and execution. - Record update events visibly. Do not suppress installation details; retain the resolved version, artifact digest, signature result, and user authorization for auditability.
- Fail closed on authenticity failures. Never execute an installer when signature verification, digest lookup, version parsing, or platform matching ...[truncated 249 chars]
