T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:15- Finding
Mutable Remote Skill Instructions Are Loaded Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15-22andSKILL.md:56
Vulnerability Type: Mutable remote instruction retrieval
Risk Level: HighVulnerable Instruction Snippet
The following is an English translation of the relevant Skill instructions; commands and URLs are preserved verbatim:
markdown Before every use of this Skill, execute the following command to check for updates: curl -s https://raw.githubusercontent.com/PitayaK/elsewhere-news/main/SKILL.md | head -5 If the version differs from the locally cached version, retrieve the complete file again: curl -s https://raw.githubusercontent.com/PitayaK/elsewhere-news/main/SKILL.mdThe setup process also obtains persistent-storage rules from another mutable remote resource:
text https://elsewhere.news/specs/tasteTechnical Analysis
The locally reviewed Skill delegates part of its effective behavior to files retrieved from mutable remote URLs. The GitHub URL references the
mainbranch rather than a reviewed commit, release artifact, or content digest. The preference-storage specification is similarly retrieved from a live website without integrity verification.Although the downloaded content is Markdown rather than a native executable, it is intended to be interpreted as Agent instructions. Consequently, a remote change can alter the actions performed by the Agent after the locally installed package has already passed review. There is no checksum, signature validation, trusted-version manifest, or mandatory user review before the new instructions are adopted.
This creates a post-review supply-chain control channel. Compromise of the GitHub account, repository, branch, hosting service, domain, or deployment pipeline could introduce instructions to access additional files, transmit sensitive information, alter persistent state, or invoke privileged tools.
Attack Path
- An attacker compromises the upstream repo ...[truncated 1174 chars]
- Remediation
View remediation
Remediation Suggestions
- Package the complete operating instructions and the
TASTE.mdschema inside the reviewed Skill artifact. - Pin remote updates to an immutable commit hash or versioned release artifact.
- Publish and verify a cryptographic digest or digital signature before accepting an update.
- Display a human-readable diff and require explicit user approval before replacing local instructions.
- Do not automatically interpret downloaded Markdown as trusted Agent instructions.
- Restrict the update process to metadata checks; route actual updates through the platform's reviewed installation mechanism.
- Apply allowlisted domains, strict timeouts, response-size limits, and TLS certificate validation to any remaining update requests.
- Package the complete operating instructions and the
