T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:25- Finding
Unverified Remote Installer Executed for Full-Stack Installation
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent persistent-memory tool, but its setup asks users or agents to run unverified remote installers and may expose a local memory server on the network.
Review this before installing. Prefer a pinned, checksum-verified Demarkus installer or inspect the downloaded script manually before running it. Use remote mode only with a server you trust, avoid storing secrets or private user data in journals, and configure any local server to bind to localhost with no firewall opening unless you explicitly need network access.
SKILL.md:25Unverified Remote Installer Executed for Full-Stack Installation
SKILL.md:53Unverified Remote Installer Executed for Client-Only Installation
SKILL.md:81Unpinned Package Download and Execution Through npx
SKILL.md:148Local Server Exposed on All Interfaces with Automatic Firewall Modification
The skill instructs the agent to fetch and execute a remote shell installer via curl ... | bash, which gives unaudited code immediate execution on the host. This is especially risky because the capability is introduced during setup for a memory tool, making the privilege expansion unjustified and easy to abuse through upstream compromise.
The | bash pattern chains network retrieval directly into shell execution, eliminating the opportunity for inspection and magnifying the impact of any upstream compromise. In the context of an agent skill, this is especially dangerous because it encourages automated execution of remote code on behalf of the user.
If not found, install the full stack (client, server, MCP binary, daemon):
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash
Store the token and register demarkus-mcp with mcporter:
The journaling guidance tells the agent to record session notes, key decisions, and what it learned, which encourages persistence of conversation context into long-lived storage. In a memory skill, that materially increases the risk of leaking secrets, personal data, or proprietary information across sessions or to a remote server.
### Journaling
Use `demarkus.mark_append` to record session notes, key decisions, and what you learned. Each entry should include a date and a brief summary. This is your running log — append freely, never overwrite.
### Thoughts and Reflections
The trigger phrases are unusually broad, including requests to remember things across sessions, store thoughts, reflections, or 'give the agent a soul.' This increases the chance the skill activates in unrelated contexts and captures or persists sensitive data that the user did not intend to store.
The skill's stated purpose is memory/document storage, but the local setup installs and runs a full server stack exposed on all interfaces and opens a firewall port. That grants unnecessary network-facing capability and increases attack surface far beyond what is required for simple local persistence.
The Linux setup uses sudo cat /etc/demarkus/initial-token.txt, introducing privileged execution into an agent-driven flow. Even though the command is limited, normalizing sudo use in setup increases risk and can expose sensitive tokens to broader shell history, logs, or misuse in adjacent steps.
if [ "$(uname)" = "Darwin" ]; then
TOKEN=$(cat ~/.demarkus/initial-token.txt)
else
TOKEN=$(sudo cat /etc/demarkus/initial-token.txt)
fi
demarkus token add mark://localhost "$TOKEN"
Using npx -y mcporter without pinning a version allows whatever package version is current at execution time to be fetched and run. That creates a supply-chain risk and makes behavior non-deterministic, especially in a skill that configures a bridge used for persistent memory operations.
The skill is explicitly designed for session persistence and versioned storage, so persistence itself is intentional rather than deceptive. However, in security terms it is still a real risk because it enables accumulation of sensitive data over time and broadens the consequences of accidental or malicious writes.
## Tools
- `demarkus.mark_fetch` — read a document
- `demarkus.mark_publish` — write or update (fetch first, use returned version as expected_version)
- `demarkus.mark_append` — append content, no fetch required
- `demarkus.mark_list` — list documents and directories
- `demarkus.mark_versions` — full version history
The privacy section claims no data is sent to third parties, but the documented workflow downloads installer code from GitHub and supports remote servers explicitly provided by the user. This mismatch can mislead users and agents about trust boundaries, causing sensitive data to be handled under false assumptions.
Fetching an external script from GitHub and executing it directly introduces a classic supply-chain risk. If the repository, branch, delivery path, or transit controls are compromised, arbitrary code can run on the target machine during setup.
If not found, install the full stack (client, server, MCP binary, daemon):
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash
Store the token and register demarkus-mcp with mcporter:
Even in client-only mode, the skill still uses a remote fetched installer script piped to bash. Although the attack surface is somewhat smaller than the full-stack install, it still allows arbitrary code execution from an external source without verification.
Install the client binaries (no server, no daemon):
curl -fsSL https://raw.githubusercontent.com/latebit-io/demarkus/main/install.sh | bash -s -- --client-only
Store the token and register demarkus-mcp with mcporter:
No suspicious patterns detected.