T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:171- Finding
Unverified Remote Script Executed Through a Shell Pipeline
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 171
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code
bash curl -fsSL https://get.my-cli.dev | shTechnical Analysis
The CLI README template retrieves a shell script from an external domain and pipes the response directly into
sh. The command does not pin an immutable release, verify a cryptographic checksum or signature, save the script for inspection, or establish that the placeholder domain is a trusted distribution source.Consequently, the effective code is not contained in the reviewed Skill and can change at any time. Compromise, reassignment, or malicious control of the domain, its hosting infrastructure, DNS resolution, or release process would allow arbitrary shell commands to be returned and executed.
The command appears in documentation rather than an automatically invoked script. Nevertheless, it is a copy-ready installation instruction in a Skill intended to produce reusable developer documentation. An agent may reproduce it in generated documentation, after which a user may execute it as an installation command. Remote code execution is unnecessary for the Skill's declared technical-writing functionality and exceeds the minimum privileges needed to provide a documentation template.
Attack Path
- An agent uses or reproduces the CLI README template from
SKILL.md. - The generated documentation retains the
curl | shinstallation command. - An attacker controls or compromises
get.my-cli.dev, its hosting environment, DNS path, or publication process. - A user follows the generated installation instructions.
curldownloads the attacker-controlled response.- The shell immediately executes that response without integrity verification or prior inspection.
- The payload performs arbitrary actions using the invoking user's permissions.
Impact Assessment
Successful exploitation provides arbitra ...[truncated 693 chars]
- An agent uses or reproduces the CLI README template from
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shpipeline from the template. - Prefer an established package manager or verified official release channel.
- If a script-based installer is required:
- Pin an immutable version.
- Download the installer to a local file.
- Publish and verify a cryptographic checksum or signature through an independent trusted channel.
- Display or inspect the downloaded script before execution.
- Require explicit user confirmation before running it.
- Run it without elevated privileges unless a documented operation strictly requires elevation.
- Replace the placeholder domain with a clearly non-executable example, or label the command explicitly as unsafe pseudocode that must not be copied.
- Add documentation security guidance prohibiting remote responses from being piped directly into a shell.
A safer illustrative pattern is:
bash version="1.2.3" curl -fL -o install.sh \ "https://downloads.example.invalid/my-cli/${version}/install.sh" echo "EXPECTED_SHA256 install.sh" | sha256sum --check - less install.sh sh install.shThe checksum must be obtained from a trusted, independently authenticated release source. The
.invaliddomain above is intentionally non-routable and should be replaced only with a verified official source.- Remove the direct
