T03 · Remote Payload Retrieval and Execution
- Location
install.sh:4- Finding
Documented installer executes a remote script and subsequently retrieves mutable source code
- Content
View full analysis
/dev/null 2>&1; then git clone --depth 1 "$REPO_URL" "$repo_dir" else need_command curl need_command tar mkdir -p "$repo_dir" curl -fsSL "$TARBALL_URL" | tar -xz -C "$tmp_dir" ``` `install.sh:81-91`: ```bash if npm view "$PACKAGE_NAME" version --registry=https://registry.npmjs.org >/dev/null 2>&1; then if npm install -g "$PACKAGE_NAME"; then echo "Installed qg CLI from npm package: $PACKAGE_NAME" else echo "npm package install failed; falling back to source install." install_from_source fi else echo "npm package is not available yet; falling back to source install." install_from_source fi ``` ### Technical Analysis The documented one-line installation command pipes network content directly into Bash. Although the initial `raw.githubusercontent.com` URL is pinned to a commit, the downloaded installer does not continue using that pinned revision. It clones the repository’s mutable default branch or downloads `main.tar.gz`. No commit verification, checksum validation, or cryptographic signature verification occurs before the retrieved project is built and installed. Consequently, the effective code executed and installed can differ from the code represented by the pinned installer revision and from the code reviewed during this audit. The installer also supports `QG_SKILL_REPO_URL` and `QG_SKIL ...[truncated 1822 chars]- Remediation
View remediation
" ``` 5. Reject arbitrary source URL overrides by default. If mirrors are required, validate them against an allowlist and still require the expected content hash. 6. Download archives to a file first, verify the expected hash, inspect archive paths, and only then extract them. 7. Avoid global installation and automatic installation into both agent platforms. Let the user select a destination and use a project-local or user-scoped installation. 8. Clearly document all filesystem modifications, network destinations, lifecycle scripts, and code-execution steps before requesting user approval. ]]>
