T03 · Remote Payload Retrieval and Execution
- Location
INSTALL.md:6- Finding
Unpinned Remote Installation Script Is Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
INSTALL.md, line 6
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable code:
bash curl -fsSL https://raw.githubusercontent.com/planetarium/a2a-x402-wallet/main/scripts/install.sh | shTechnical Analysis
The installation command retrieves a shell script from the mutable
mainbranch of an external repository and immediately executes it. The downloaded content is not pinned to an immutable commit or release, saved for inspection, authenticated with a cryptographic signature, or checked against a trusted digest.HTTPS protects the connection in transit but does not ensure that the repository account, branch contents, or upstream installation script remain trustworthy. The script is also absent from the audited project, so its actual commands, downloaded artifacts, filesystem changes, and privilege behavior cannot be verified from this package.
Direct execution is not necessary for the Skill's declared wallet and A2A functionality. A versioned binary or locally included, reviewable installer with integrity verification would provide the required installation capability with substantially less supply-chain risk.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the mutable installation script.
- The attacker modifies
scripts/install.shon themainbranch or causes it to retrieve a malicious secondary payload. - A user or AI agent follows
INSTALL.mdand invokes the documented command. curlstreams the attacker-controlled content directly intosh.- The payload runs with the invoking user's privileges and can access files, environment variables, wallet data, authentication tokens, and network resources available to that user.
- Because this is a wallet-related tool, the payload could specifically target private keys or alter payment operations.
Impact Assess
...[truncated 451 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not pipe remotely retrieved content directly into a shell.
- Pin the installer to an immutable release tag and commit rather than the mutable
mainbranch. - Download the installer to a local file and require review before execution.
- Publish SHA-256 or stronger digests through a separately trusted channel and verify them before execution.
- Cryptographically sign installer scripts and release artifacts, and document mandatory signature verification.
- Include the installer in the audited Skill package where practical.
- Ensure the installer runs without administrator privileges unless a narrowly scoped operation explicitly requires elevation.
- Pin and verify every secondary artifact downloaded by the installer.
