T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:101- Finding
Unverified Remote Code Execution Through Installation and Upgrade Workflows
- Content
View full analysis
&& ./setup` 3. If `bun` is not installed: `curl -fsSL https://bun.sh/install | bash` ``` The upgrade workflow additionally retrieves mutable repository content and immediately executes it: ```bash cd "$INSTALL_DIR" STASH_OUTPUT=$(git stash 2>&1) git fetch origin git reset --hard origin/main ./setup ``` For vendored installations: ```bash PARENT=$(dirname "$INSTALL_DIR") TMP_DIR=$(mktemp -d) git clone --depth 1 https://github.com/garrytan/gstack.git "$TMP_DIR/gstack" mv "$INSTALL_DIR" "$INSTALL_DIR.bak" mv "$TMP_DIR/gstack" "$INSTALL_DIR" cd "$INSTALL_DIR" && ./setup rm -rf "$INSTALL_DIR.bak" "$TMP_DIR" ``` ### Technical Analysis The `curl | bash` pattern passes remotely retrieved content directly to a shell. No immutable version, expected digest, or cryptographic signature is verified before execution. Consequently, the effective code can change after the Skill package has been reviewed. The upgrade workflow has the same trust-boundary problem: it resets the installation to the mutable `origin/main` branch or clones the current repository head and then immediately runs `./setup`. The workflow can also be configured to upgrade automatically, removing per-update user review. The referenced `setup` executable is not present in the supplied artifact. Its behavior and privilege requirements therefore could not be audited, even though multiple instructions require its execution. ### Attack Path 1. An attacker compr ...[truncated 1001 chars]- Remediation
View remediation
