T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:58- Finding
Unverified Remote Installer Scripts Executed Directly by Shells
- Content
View full analysis
- Remediation
View remediation
/install.sh" ``` 5. Publish and verify a pinned SHA-256 checksum before execution: ```bash echo " oo-installer.sh" | sha256sum --check - ``` 6. Prefer publisher-backed cryptographic signature verification over checksums alone, with the trusted public key distributed through an independent channel. 7. Allow the user to inspect the downloaded artifact before running it. 8. Request explicit user approval immediately before executing any installer. 9. Run installation with the lowest practical privileges; do not request administrator or root access unless a specific installation target requires it. 10. Apply equivalent version pinning, signature validation, separate download, and explicit approval controls to the PowerShell installer. 11. Document the artifact source, expected publisher identity, version, checksum, installation destinations, and permissions required. ]]>
