T03 · Remote Payload Retrieval and Execution
- Location
install.sh:41- Finding
Mutable Remote Payload Retrieval and Execution During Installation
- Content
View full analysis
/dev/null || npm install --silent else echo "📦 安装npm依赖..." npm install --silent fi ``` ### Technical Analysis The installer clones the current default branch of an external GitHub repository without selecting an immutable commit, verifying a release signature, or validating a cryptographic checksum. The effective application payload can therefore change after this Skill package has been reviewed. After obta ...[truncated 2656 chars]- Remediation
View remediation
