T03 · Remote Payload Retrieval and Execution
- Location
scripts/setup.sh:34- Finding
Unverified Remote Installer Is Downloaded and Executed Through a Shell
- Content
View full analysis
/dev/null; then log_warning "未找到uv工具,正在安装..." curl -LsSf https://astral.sh/uv/install.sh | sh if [[ $? -eq 0 ]]; then log_success "uv安装成功" # 添加uv到PATH export PATH="$HOME/.cargo/bin:$PATH" else log_error "uv安装失败" return 1 fi fi ``` The same unsafe installation instruction is presented to users in two documentation files: ```bash curl -LsSf https://astral.sh/uv/install.sh | sh ``` ### Technical Analysis The script retrieves a mutable response from an external URL and passes it directly to `sh`. There is no version pinning, cryptographic signature verification, checksum validation, local inspection, or separation between download and execution. HTTPS provides transport protection but does not establish that the retrieved script is immutable or safe. Compromise of the hosting infrastructure, publishing process, domain, or relevant trust chain could replace the installer after this Skill has already passed review. Installing `uv` is relevant to the declared functionality, but immediate execution of a mutable remote script is not the minimum-privilege or minimum-risk way to satisfy that dependency. A system package, pinned release artifact, or separately downloaded and verified installer would avoid this execution pattern. ### Attack Path 1. A user or Agent invokes `./scripts/setup.sh install`. 2. The script determines that `uv` is not currently available. 3. The script requests the current contents of `https://astral.sh/uv/install.sh`. 4. The response is immediately interpreted by `sh`. 5. If the remote source or delivery path has been compromised, attacker-controlled commands execute with all privileges and fi ...[truncated 757 chars]- Remediation
View remediation
/install.sh" printf '%s %s\n' "" "/tmp/uv-installer.sh" | sha256sum --check - sh /tmp/uv-installer.sh rm -f /tmp/uv-installer.sh ``` The actual release URL and digest must come from authenticated, publisher-supported release metadata. ]]>
