T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:18- Finding
Unreviewed Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 18
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://raw.githubusercontent.com/colbymchenry/codegraph/main/install.sh | sh # No Node requiredTechnical Analysis
The installation instructions retrieve
install.shfrom the mutablemainbranch of a personal GitHub repository and pipe its contents directly intosh. The downloaded script is not included in the audited project, pinned to an immutable commit, checked against a cryptographic digest, or authenticated with a release signature.Consequently, the code executed by this command can change after the Skill has been reviewed. Piping the response directly to a shell also prevents meaningful inspection before execution. The use of HTTPS protects the network connection under normal conditions but does not protect against repository compromise, publisher-account takeover, or a malicious later update to the referenced branch.
This behavior exceeds the minimum privileges necessary for the declared installation function because the documentation already provides npm-based alternatives; arbitrary mutable shell-script execution is not intrinsically required to install a local code-indexing tool.
Attack Path
- An attacker compromises the GitHub repository, maintainer account, or another component controlling the remote installer.
- The attacker changes
install.shon the referencedmainbranch. - A user or automated Agent follows the documented installation command.
curlretrieves the attacker's current script without version or integrity verification.shimmediately executes the response with the privileges of the invoking user.- The payload can access or alter any resources available to that user.
Impact Assessment
Successful exploitation provides arbitrary command execution under the invoki ...[truncated 469 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shinstallation method. - Prefer a project-local package installation with an exact, audited version recorded in a lockfile.
- If a standalone installer is necessary, publish it as a versioned release artifact rather than retrieving it from a mutable branch.
- Pin the artifact to an immutable release or commit and publish a SHA-256 or stronger cryptographic digest.
- Verify the digest or a trusted release signature before execution.
- Download the installer to a file first, permit inspection, and execute it only after verification.
- Ensure the installer operates without elevated privileges and clearly documents every filesystem or configuration change.
- Remove the direct
