Back to skill

Security audit

Paperzilla

Security checks for vulnerabilities and agentic risk

Overview

The Paperzilla skill matches its stated CLI purpose, but its Linux install and update steps use an unverified download and system-wide installation that users should review first.

Install only if you trust the Paperzilla release source. Prefer Homebrew or Scoop where appropriate, or use a pinned release with checksum or signature verification and a user-owned bin directory instead of piping a latest download into tar and moving it with sudo.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Warning
Location
SKILL.md:30
Finding

Unverified Mutable Release Binary Download and System-Wide Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 30–31 and 86–87
Vulnerability Type: Remote payload retrieval through an unverified mutable release artifact
Risk Level: Medium

Vulnerable Code

Installation instructions at lines 30–31:

bash
curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz
sudo mv pz /usr/local/bin/

Update instructions at lines 86–87:

bash
curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz
sudo mv pz /usr/local/bin/

Technical Analysis

These commands retrieve a precompiled executable from a mutable latest release URL, stream the response directly into tar, and install the extracted executable into a system-wide command directory. No pinned version, expected cryptographic hash, or signature verification is provided.

Although the artifact is hosted on GitHub under the organization associated with the documented project, transport security alone does not establish artifact integrity or publisher authenticity. Compromise of the repository, release-publishing credentials, release workflow, or hosted artifact could cause the same reviewed command to retrieve different executable code later.

Streaming the archive directly into tar also prevents verification before extraction. The silent curl option suppresses useful diagnostics, while omission of --fail can make HTTP failures less explicit. The subsequent sudo mv crosses a least-privilege boundary by placing the unverified binary in /usr/local/bin, where it can replace an existing pz executable and become the default command resolved by users.

The installation command does not itself run the downloaded binary as root. However, later documented operations such as pz login, pz project, and pz feed execute it with the invoking user's permissions and may expose authentication material and service da ...[truncated 1663 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin installation instructions to an explicit reviewed release version rather than using the mutable latest URL.
  2. Publish SHA-256 checksums through a separately protected release process and verify the downloaded archive before extraction.
  3. Prefer cryptographic release signatures or provenance attestations, and verify them against a documented, trusted public key.
  4. Download into a newly created temporary directory instead of streaming directly into tar:
    bash
    set -euo pipefail
    version="X.Y.Z"
    tmpdir="$(mktemp -d)"
    trap 'rm -rf "$tmpdir"' EXIT
    
    curl --fail --show-error --location \
      --output "$tmpdir/pz_linux_amd64.tar.gz" \
      "https://github.com/paperzilla-ai/pz/releases/download/v${version}/pz_linux_amd64.tar.gz"
    
    echo "EXPECTED_SHA256  $tmpdir/pz_linux_amd64.tar.gz" | sha256sum --check -
    tar -tzf "$tmpdir/pz_linux_amd64.tar.gz"
    tar -xzf "$tmpdir/pz_linux_amd64.tar.gz" -C "$tmpdir"
    
  5. Validate that the archive contains only expected paths and files before extraction.
  6. Install into a user-owned directory such as $HOME/.local/bin unless system-wide availability is specifically required.
  7. If /usr/local/bin installation is necessary, verify the artifact before invoking sudo and use an explicit destination with controlled ownership and permissions.
  8. Apply the same pinned-version and provenance-verification requirements to the documented update workflow.
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description says to trigger when users ask to check feeds, list projects, inspect paper details, tune recommendations, or automate feed workflows, but it does not define exact trigger phrases, scope limits, or exclusion conditions. Terms like 'inspect paper details' and 'automate feed workflows' are broad enough to overlap with general research-assistant requests, which could cause unintended invocation.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 31)May include surrounding context.

Linux

bash
curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz
sudo mv pz /usr/local/bin/

Build from source (Go 1.23+)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 87)May include surrounding context.

Linux

bash
curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz
sudo mv pz /usr/local/bin/

Build from source (Go 1.23+)

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · SKILL.md (reported line 94)May include surrounding context.

Linux

bash
curl -sL https://github.com/paperzilla-ai/pz/releases/latest/download/pz_linux_amd64.tar.gz | tar xz
sudo mv pz /usr/local/bin/

Build from source (Go 1.23+)

Static analysis

No suspicious patterns detected.