T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:14- Finding
Unverified Remote Installer Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 14
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -fsSL https://cli.inference.sh | sh && infsh loginTechnical Analysis
The quick-start command downloads a mutable shell script from an external server and immediately pipes it into
sh. The downloaded content is not inspected, version-pinned, or independently authenticated before execution.HTTPS protects the connection in transit under normal conditions, but it does not guarantee that the server or its published script remains trustworthy. An attacker who compromises the hosting service, deployment pipeline, domain, or relevant TLS trust path could replace the installer with arbitrary shell commands.
The document states that the installer verifies the SHA-256 checksum of the CLI binary. This does not establish the integrity of the installer itself because the unverified script performs the verification. A malicious installer can bypass, falsify, or remove that check.
Executing remote code is not the minimum privilege necessary to install the documented CLI. The existing manual installation and checksum-verification option can provide the required functionality without directly executing a mutable network response.
Attack Path
- An attacker compromises
cli.inference.sh, its publishing infrastructure, or another part of the delivery path. - The attacker replaces the expected installer response with a malicious shell script.
- A user or agent follows the documented quick-start command.
curlretrieves the attacker-controlled response.- The pipe sends the response directly to
shwithout prior review or independent integrity validation. - The payload executes with all permissions available to the invoking user.
- The payload may read accessible files and credentials, alter user configuration, downloa ...[truncated 773 chars]
- An attacker compromises
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstallation pattern from the quick-start instructions. - Publish versioned CLI artifacts rather than directing users to a mutable installer endpoint.
- Require users to download the artifact and checksum separately, then verify integrity before execution.
- Pin the expected CLI version and SHA-256 digest in reviewed documentation or obtain a signed checksum manifest through an independently trusted channel.
- Prefer cryptographic signatures with a documented, pinned public key over checksums hosted on the same infrastructure as the binary.
- Ensure installation does not require administrative privileges and explicitly warn users not to run installation commands as
rootor throughsudo. - If an installer script remains available, instruct users to save and inspect it before execution rather than piping it directly into a shell.
A safer workflow would resemble:
bash curl -fSLo infsh https://dist.inference.sh/cli/<pinned-version>/<platform>/infsh curl -fSLo checksums.txt https://dist.inference.sh/cli/<pinned-version>/checksums.txt grep ' infsh$' checksums.txt | sha256sum --check - chmod 0755 infshThe artifact version, platform path, and trusted digest or signature-verification procedure must be explicitly documented.
- Remove the
