T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Mutable Release Binary Download and System-Wide Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 30–31 and 86–87
Vulnerability Type: Remote payload retrieval through an unverified mutable release artifact
Risk Level: MediumVulnerable Code
Installation instructions at lines 30–31:
bash curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz sudo mv pz /usr/local/bin/Update instructions at lines 86–87:
bash curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz sudo mv pz /usr/local/bin/Technical Analysis
These commands retrieve a precompiled executable from a mutable
latestrelease URL, stream the response directly intotar, and install the extracted executable into a system-wide command directory. No pinned version, expected cryptographic hash, or signature verification is provided.Although the artifact is hosted on GitHub under the organization associated with the documented project, transport security alone does not establish artifact integrity or publisher authenticity. Compromise of the repository, release-publishing credentials, release workflow, or hosted artifact could cause the same reviewed command to retrieve different executable code later.
Streaming the archive directly into
taralso prevents verification before extraction. The silentcurloption suppresses useful diagnostics, while omission of--failcan make HTTP failures less explicit. The subsequentsudo mvcrosses a least-privilege boundary by placing the unverified binary in/usr/local/bin, where it can replace an existingpzexecutable and become the default command resolved by users.The installation command does not itself run the downloaded binary as root. However, later documented operations such as
pz login,pz project, andpz feedexecute it with the invoking user's permissions and may expose authentication material and service da ...[truncated 1663 chars]- Remediation
View remediation
Remediation Suggestions
- Pin installation instructions to an explicit reviewed release version rather than using the mutable
latestURL. - Publish SHA-256 checksums through a separately protected release process and verify the downloaded archive before extraction.
- Prefer cryptographic release signatures or provenance attestations, and verify them against a documented, trusted public key.
- Download into a newly created temporary directory instead of streaming directly into
tar:bash set -euo pipefail version="X.Y.Z" tmpdir="$(mktemp -d)" trap 'rm -rf "$tmpdir"' EXIT curl --fail --show-error --location \ --output "$tmpdir/pz_linux_amd64.tar.gz" \ "https://github.com/paperzilla-ai/pz/releases/download/v${version}/pz_linux_amd64.tar.gz" echo "EXPECTED_SHA256 $tmpdir/pz_linux_amd64.tar.gz" | sha256sum --check - tar -tzf "$tmpdir/pz_linux_amd64.tar.gz" tar -xzf "$tmpdir/pz_linux_amd64.tar.gz" -C "$tmpdir" - Validate that the archive contains only expected paths and files before extraction.
- Install into a user-owned directory such as
$HOME/.local/binunless system-wide availability is specifically required. - If
/usr/local/bininstallation is necessary, verify the artifact before invokingsudoand use an explicit destination with controlled ownership and permissions. - Apply the same pinned-version and provenance-verification requirements to the documented update workflow.
- Pin installation instructions to an explicit reviewed release version rather than using the mutable
