T03 · Remote Payload Retrieval and Execution
- Location
README.md:20- Finding
Mutable remote installer scripts are executed directly by command interpreters
- Content
View full analysis
Vulnerability Details
File Location:
README.md:20-25; duplicated for Unix-like systems inSKILL.md:25-28
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: CriticalVulnerable Code
README.md:20-25:bash # macOS / Linux curl -LsSf https://astral.sh/uv/install.sh | sh # Windows powershell -ExecutionPolicy ByPass -c "irm https://astral.sh/uv/install.ps1 | iex"SKILL.md:25-28:bash 1. Install uv: ```bash curl -LsSf https://astral.sh/uv/install.sh | shtext ### Technical Analysis Both installation methods retrieve mutable content from an external URL and pass it directly to a command interpreter. The downloaded payload is not pinned to a reviewed version and is not verified using a cryptographic digest or publisher signature before execution. The PowerShell command additionally uses `-ExecutionPolicy ByPass`, removing a local policy barrier for the downloaded script. Although `astral.sh` is presented as the official source for `uv`, direct interpreter piping leaves execution dependent on the continuing integrity of the remote publication infrastructure, DNS resolution, TLS trust chain, and upstream account security. The effective code can change after this Skill package has been reviewed. This behavior is used to install a declared prerequisite, but it is not the least-risk installation method and exceeds what is necessary because verified, versioned installation mechanisms can be used instead. ### Attack Path 1. An attacker compromises the remote installer publication process, hosting account, domain, or another relevant distribution dependency. 2. The attacker replaces the installer response with commands of their choice. 3. A user follows the documented setup command. 4. `sh` or PowerShell immediately interprets the response without presenting it for review or checking a pinned digest. 5. The attacker's commands execute with all ...[truncated 622 chars]- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | shandirm | iexinstallation instructions. - Direct users to a trusted operating-system package manager with an explicitly pinned package version where possible.
- Otherwise, download a versioned release artifact to disk without executing it.
- Verify the artifact against a hardcoded SHA-256 digest or a trusted publisher signature obtained through an independently authenticated channel.
- Present the verified script for inspection before execution.
- Do not use PowerShell execution-policy bypasses in installation instructions.
- Document that installation must occur without administrative privileges unless a specific platform package manager requires elevation.
- Remove all
