T03 · Remote Payload Retrieval and Execution
- Location
references/install-nodejs.md:20- Finding
Remote installation scripts are executed directly through shell pipelines
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Wenjuanxing CLI skill, but its installer can globally install mutable code, use sudo, overwrite agent skill files, and handle API credentials with insufficient safeguards.
Review before installing. Prefer a pinned, reviewed wjx-cli version; avoid sudo/global installs when possible; do not run curl-to-bash setup commands; confirm any skill-file overwrite before accepting it; treat API keys and generated SSO URLs as secrets; and require explicit confirmation before delete, clear, account, admin, department, tag, or response-submission actions.
references/install-nodejs.md:20Remote installation scripts are executed directly through shell pipelines
SKILL.md:18Mutable npm packages are installed globally and can forcibly replace agent Skill files
setup.sh:257API keys may be exposed through process arguments and transmitted to plaintext custom endpoints
The declared purpose is an end-user guide/skill for operating wjx-cli survey functions. The supplied code does not implement survey operations, response querying, exporting, analysis, or account/contact management. Instead, it is a build/packaging utility for distributing the skill itself. This is a materially different primary purpose, so the description does not accurately represent the code chunk.
Piping directly into bash is a classic unsafe chaining pattern because it executes remote content immediately without user validation. Although this step is not explicitly privileged, it still enables arbitrary code execution in the user's environment and could modify shell startup files or credentials.
brew install node@20
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash source ~/.bashrc # 或 source ~/.zshrc nvm install 20
This command chains network retrieval directly into privileged shell execution (curl ... | sudo -E bash -), eliminating any opportunity for inspection before code runs as root. In skill documentation, this is especially dangerous because users may copy-paste it verbatim, turning documentation into a delivery mechanism for privilege-compromising code if the source is ever malicious or compromised.
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
The command -v sudo && sudo npm install -g wjx-cli@latest chain makes privilege escalation part of automated fallback behavior. In the context of installing a remote npm package, this chaining increases the chance that users unintentionally execute privileged network-sourced code, magnifying supply-chain compromise impact to full root execution.
if npm install -g wjx-cli@latest; then
return 0
fi
if command -v sudo &> /dev/null && sudo npm install -g wjx-cli@latest; then
return 0
fi
print_error "wjx-cli 升级失败"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
echo "请安装 Node.js 20+ 后重新运行本脚本:"
echo ""
echo " macOS: brew install node"
echo " Ubuntu: curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
echo " CentOS: curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
echo " Windows: winget install OpenJS.NodeJS"
echo " 通用: https://nodejs.org 下载安装"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
echo "请安装 Node.js 20+ 后重新运行本脚本:"
echo ""
echo " macOS: brew install node"
echo " Ubuntu: curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
echo " CentOS: curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
echo " Windows: winget install OpenJS.NodeJS"
echo " 通用: https://nodejs.org 下载安装"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
echo "请安装 Node.js 20+ 后重新运行本脚本:"
echo ""
echo " macOS: brew install node"
echo " Ubuntu: curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
echo " CentOS: curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
echo " Windows: winget install OpenJS.NodeJS"
echo " 通用: https://nodejs.org 下载安装"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
echo "请安装 Node.js 20+ 后重新运行本脚本:"
echo ""
echo " macOS: brew install node"
echo " Ubuntu: curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash - && sudo apt-get install -y nodejs"
echo " CentOS: curl -fsSL https://rpm.nodesource.com/setup_20.x | sudo bash - && sudo yum install -y nodejs"
echo " Windows: winget install OpenJS.NodeJS"
echo " 通用: https://nodejs.org 下载安装"
The skill clearly directs the agent to execute shell commands such as global npm installs and CLI configuration, but it does not declare any explicit tool scope or allowed-tools boundary. This weakens least-privilege controls and can let the skill run system-modifying actions in environments that rely on manifest-level permissions for safety review.
The activation description is very broad and can trigger on common words like survey, form, questionnaire, NPS, or related Chinese terms without requiring clear user intent to use this specific CLI. Overbroad routing increases the chance that the agent invokes installation, configuration, or data-handling workflows in contexts where the user only wanted general advice, creating unnecessary exposure to shell actions and sensitive survey data.
The skill tells the AI to perform a global npm install and run follow-up configuration commands, which are system-modifying actions, but it does not require an upfront safety notice or explicit user approval before changing the host environment. This can lead to unexpected software installation, PATH changes, and persistence on the user's machine.
The workflow instructs the AI to accept a user-provided API key and run initialization that likely stores the credential in local config, while only briefly saying not to echo the full key. Without a clear warning about credential persistence, storage location, reuse, and consent, the skill risks mishandling secrets and exposing access to survey/account data if the local machine or logs are compromised.
The package description is written entirely in Chinese and presents the skill as operating in that language, with no indication that users can choose another language or locale. This can violate language/locale policy when a skill implicitly constrains interaction language without explicit opt-in or documented regional justification.
This markdown file documents a command that processes encrypted webhook payloads and explicitly includes sensitive inputs like --app_key, --raw_body, signatures, and client IP fields, but it provides no warning about keeping these values confidential or avoiding exposure in shell history/logs. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors affecting privacy or sensitive data handling.
The documentation includes multiple destructive delete operations for departments, tags, admins, contacts, and subaccounts, but only contacts deletion is explicitly marked as irreversible. In an agent skill context, omission of consistent warnings and confirmation guidance can cause the agent or user to execute high-impact administrative changes unintentionally, especially since these commands affect organizational identity and access structures.
The SSO commands generate passwordless login URLs for subaccounts, partner accounts, and legacy user-system users, but the documentation does not warn that these links are sensitive authentication artifacts. In a skill used by an automated agent, this increases the risk of accidental exposure in chat history, logs, screenshots, or redirects, enabling unauthorized access if a generated link is leaked.
The document is written entirely in Chinese and uses mandatory language such as '必须' and '统一用单引号包裹' without indicating that users may choose another language or locale. Under the policy rule, a skill that effectively forces a specific language/locale without opt-in is a natural-language policy concern.
Using sudo -E preserves the caller's environment while executing a remotely piped script as root, increasing the attack surface beyond ordinary privileged execution. Environment inheritance can influence script behavior or interpreter resolution, and combined with curl ... | bash creates a particularly risky installation pattern.
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
Using sudo -E preserves the caller's environment while executing a remotely piped script as root, increasing the attack surface beyond ordinary privileged execution. Environment inheritance can influence script behavior or interpreter resolution, and combined with curl ... | bash creates a particularly risky installation pattern.
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
Line L005 states that JSONL 'must use Chinese strings' for key values, which forces a specific language format. This is reinforced by L038 indicating the first-line language defaults to zh, with no opt-in or explanation that the skill is intentionally region-specific.
This markdown file presents all user-facing instructions in a single language and does not provide an opt-in, alternative locale, or justification for restricting usage to Chinese. That creates a natural-language locale policy concern because users are implicitly forced into one language without being given a choice.
This shell script's user-facing title and operational guidance are written in Chinese, and subsequent prompts/help text throughout the file continue that assumption. Because the file provides no user opt-in, alternate locale, or justification for a Chinese-only experience, it conflicts with the policy against forcing a specific language without user choice.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
local missing=0
root="$(resolve_install_root)"
for path in \
"$root/skills/wjx-cli-use/SKILL.md" \
"$root/.claude/skills/wjx-cli-use/SKILL.md" \
"$root/.claude/agents/wjx-cli-expert.md"; do
if [ ! -s "$path" ]; then
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
local missing=0
root="$(resolve_install_root)"
for path in \
"$root/skills/wjx-cli-use/SKILL.md" \
"$root/.claude/skills/wjx-cli-use/SKILL.md" \
"$root/.claude/agents/wjx-cli-expert.md"; do
if [ ! -s "$path" ]; then
No suspicious patterns detected.