T03 · Remote Payload Retrieval and Execution
- Location
scripts/install.sh:9- Finding
Unverified Remote Release Binary Download and Execution
- Content
View full analysis
"$PORT_FILE" echo "[music] starting service on port $PORT..." nohup "$BIN" > "$LOG_FILE" 2>&1 & ``` ### Technical Analysis The installer queries the mutable GitHub `releases/latest` endpoint, obtains a release asset URL, downloads the asset, and executes the extracted binary. It does not pin an audited version or verify a cryptographic digest or trusted signature. The `file` check only confirms that the extracted file resembles an ELF or Mach-O executable. It does not establish the publisher's identity, the artifact's integrity, or whether the executable is benign. Because the effective executable can change after the Skill package has been reviewed, the downloaded release is a remote mutable payload. HTTPS protects the network connection but does not protect a ...[truncated 1415 chars]- Remediation
View remediation
