T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:21- Finding
Mutable Remote Installer Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 21-40
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
text 1. **Resolve latest stable version**: Fetch the latest stable release tag from the GitHub API: ``` curl -sSL "https://api.github.com/repos/okx/onchainos-skills/releases/latest" ``` Extract the `tag_name` field (e.g., `v1.0.5`) into `LATEST_TAG`. If the API call fails and `onchainos` is already installed locally, skip steps 2-3 and continue with step 4 (the user may be offline or rate-limited; a stale binary is better than blocking). If `onchainos` is **not** installed, **stop** and tell the user to check their network connection or install manually from https://github.com/okx/onchainos-skills. 2. **Install or update**: If `onchainos` is not found, or if the cache at `~/.onchainos/last_check` (`$env:USERPROFILE\.onchainos\last_check` on Windows) is older than 12 hours: - Download the installer and its checksum file from the latest release tag: - **macOS/Linux**: `curl -sSL "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/install.sh" -o /tmp/onchainos-install.sh` `curl -sSL "https://github.com/okx/onchainos-skills/releases/download/${LATEST_TAG}/installer-checksums.txt" -o /tmp/installer-checksums.txt` - **Windows**: `Invoke-WebRequest -Uri "https://raw.githubusercontent.com/okx/onchainos-skills/${LATEST_TAG}/install.ps1" -OutFile "$env:TEMP\onchainos-install.ps1"` `Invoke-WebRequest -Uri "https://github.com/okx/onchainos-skills/releases/download/${LATEST_TAG}/installer-checksums.txt" -OutFile "$env:TEMP\installer-checksums.txt"` - Verify the installer's SHA256 against `installer-checksums.txt`. On mismatch, **stop** and warn — the installer may have been tampered with. - Execute: `sh /tmp/onchainos-install.sh` (or `& "$env:TEMP\onchainos ...[truncated 3374 chars]- Remediation
View remediation
Remediation Suggestions
- Do not automatically download and execute an installer as part of routine portfolio queries. Require the CLI to be installed through a separate, explicit setup process.
- Pin the installer to a reviewed release and immutable commit identifier rather than resolving
releases/latest. - Verify releases using a cryptographic signature rooted in a trusted public key distributed independently with the Skill. A checksum downloaded from the same repository is not sufficient against repository compromise.
- Bundle a reviewed installer or binary with the package where platform and distribution policies permit it.
- Require explicit user confirmation before every installation or upgrade and display the version, source, destination, and permissions involved.
- Avoid recurring automatic updates. Provide an opt-in update command and continue using the previously verified binary by default.
- Download into a securely created, owner-only temporary directory using unpredictable filenames. Open files with exclusive-creation semantics and prevent symbolic-link following.
- Delete installer and checksum files after verification and execution, including on failure paths.
- Execute installation with the least-privileged account available and prohibit elevation unless separately justified and approved.
- Record the expected binary hash for the pinned release in trusted Skill metadata and verify the installed binary before every relevant session.
