T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:188- Finding
Unverified Remote Installer Executed Directly by Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 188
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsS https://dotenvx.sh/ | shTechnical Analysis
The installation instruction downloads a remote script from
https://dotenvx.sh/and immediately pipes it intosh. The fetched content is not version-pinned, inspected, or verified using a cryptographic signature or checksum before execution.Although HTTPS protects the connection in transit, it does not guarantee that the server will continue serving the same reviewed payload. Compromise of the website, hosting account, deployment pipeline, or other distribution infrastructure could cause this command to execute attacker-controlled shell instructions. The payload would execute with all permissions available to the user running the command.
This behavior is not required for the Skill's declared dotenv management functionality. The same section already provides package-manager alternatives through npm and Homebrew, making direct remote shell execution avoidable.
Attack Path
- An attacker compromises the
dotenvx.shdistribution endpoint or its publishing infrastructure. - The attacker replaces or modifies the installer response with malicious shell commands.
- A user or AI agent follows the installation instructions in
SKILL.md. curlretrieves the current attacker-controlled response.- The pipe passes the response directly to
shwithout prior inspection or integrity verification. - The malicious commands execute with the invoking user's privileges.
Impact Assessment
Successful exploitation permits arbitrary command execution under the invoking account. Depending on that account's permissions and local environment, an attacker could:
- Read environment files, API keys, source code, and other accessible credentials.
- Modify project files or user configuration.
- Install additional malware or ...[truncated 387 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shinstallation option. - Prefer the existing package-manager alternatives:
bash npm install -g @dotenvx/dotenvx # or brew install dotenvx - Pin an explicit package version where reproducibility is required, and use the package manager's lockfile or integrity mechanisms.
- If a standalone installer is indispensable:
- Download it as a separate file.
- Use a version-specific immutable URL.
- Verify a publisher-provided cryptographic signature or trusted checksum.
- Inspect the downloaded script before execution.
- Execute it without elevated privileges unless a documented operation strictly requires them.
- Document the files, directories, and permissions the installer is expected to modify.
- Remove the direct
