T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:22- Finding
Mutable Remote Code and Dependencies Are Retrieved and Installed Without Integrity Pinning
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:22-24
Vulnerability Type: Remote payload retrieval and insecure software supply chain
Risk Level: HighVulnerable snippet:
bash git clone https://github.com/oywq00008-cell/BroadlinkAC-For-Agent.git cd BroadlinkAC-For-Agent pip install -r requirements-core.txtTechnical Analysis
The packaged project contains only
SKILL.md; the executable implementation and its dependency manifest are not included in the reviewed artifact. Instead, the instructions retrieve a mutable Git repository and install packages from its externally maintainedrequirements-core.txt.The clone command does not pin a commit hash or authenticated release artifact. The dependency installation also does not demonstrate exact version locking, package hashes, signature verification, or restrictions on package indexes. Consequently, the code ultimately executed can differ from the content that was available when this Skill was audited.
This behavior exceeds what can be safely reviewed within the supplied artifact. While obtaining an AC-control implementation may be necessary for the declared functionality, retrieving mutable code at runtime without integrity controls is not the minimum safe privilege or trust model.
Attack Path
- An attacker compromises the referenced GitHub account, repository, release process, or an upstream dependency source.
- The attacker modifies repository code or
requirements-core.txt, or publishes a malicious package version accepted by that manifest. - An agent follows the documented Quick Start instructions.
git cloneretrieves the modified payload.pip installprocesses the attacker-controlled dependency graph. Python package build or installation hooks may execute immediately.- The installed code subsequently runs with the privileges of the user operating the agent.
Impact Assessment
Successful exploitation can ...[truncated 546 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the reviewed implementation and dependency lock file directly in the Skill artifact.
- If remote retrieval is unavoidable, pin the repository to a full verified commit hash rather than a mutable branch.
- Prefer signed release artifacts and verify signatures or cryptographic checksums before execution.
- Lock all direct and transitive Python dependencies to exact versions.
- Install dependencies with verified hashes, such as through a hash-locked requirements file and
pip --require-hashes. - Restrict installation to explicitly approved package indexes and disable unintended extra indexes.
- Review package build metadata and avoid dependencies that require arbitrary installation hooks where possible.
- Perform installation and execution in a sandbox with limited filesystem, network, and device access.
