T03 · Remote Payload Retrieval and Execution
- Location
scripts/segment.py:35- Finding
Runtime Retrieval and Execution of Unpinned Remote Code
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This image segmentation skill is purpose-aligned, but it needs review because running it can install mutable remote code and download large unverified model files.
Use this only in an isolated Python environment you are comfortable modifying. Prefer preinstalling a pinned, reviewed segment_anything dependency and using locally verified SAM checkpoints instead of allowing first-run network installation and unverified cache downloads.
scripts/segment.py:35Runtime Retrieval and Execution of Unpinned Remote Code
scripts/segment.py:17Downloaded Model Checkpoints Are Not Integrity-Verified
The skill instructs installation directly from a remote Git repository and also notes automatic first-run installation/download behavior. Remote bootstrap of code and model artifacts without pinning, integrity verification, or trusted packaging controls is dangerous because a compromised repository, dependency, or download path could lead to arbitrary code execution in the agent environment.
ne PNG per element) python3 scripts/segment.py photo.jpg ./elements/ --all
python3 scripts/segment.py photo.jpg ./elements/ --all --grid 32
python3 scripts/segment.py photo.jpg output.png --checkpoint /path/to/sam_vit_h_4b8939.pth
## Dependencies
`segment_anything` is auto-installed on first run, or install manually:
```bash
pip install git+https://github.com/facebookresearch/segment-anything.git
pip install pillow numpy torch torchvision
~/.cache/sam/| Model | Size | Speed | Quality |
|---|---|---|---|
vit_b | ~375 MB | fastest | good |
vit_l | ~1.25 GB | medium | better |
vit_h | ~2.5 GB | slower | best |
CUDA is used automatically when a GPU is available.
The code dynamically installs software during normal execution even though the skill's purpose is image segmentation, not environment management. Installing code on demand from a remote source increases attack surface and can execute unreviewed installer logic in the current environment, making the skill materially more dangerous than its description suggests.
The script invokes a shell command to install a Python package directly from a remote GitHub repository at runtime. This creates a software supply-chain risk because unpinned remote code is fetched and executed in the user's environment, and any compromise of the repo, dependency chain, or network path could result in arbitrary code execution.
from segment_anything import SamPredictor, sam_model_registry
except ImportError:
print("Installing segment_anything...")
os.system("pip install git+https://github.com/facebookresearch/segment-anything.git -q")
from segment_anything import SamPredictor, sam_model_registry
import torch
This matches a remote bootstrap pattern because the script installs executable code directly from a Git URL at runtime, then immediately imports and uses it. That pattern is dangerous in agent skills because it bypasses normal review and package-control processes, enabling arbitrary code execution if the remote source is altered or malicious.
)...")
urllib.request.urlretrieve(url, path, reporthook=lambda b, bs, t: print(f"\r {min(b*bs,t)*100//t}%", end="", flush=True) if t > 0 else None)
print()
return path
def _load_sam(model_type, checkpoint):
try:
from segment_anything import SamPredictor, sam_model_registry
except ImportError:
print("Installing segment_anything...")
os.system("pip install git+https://github.com/facebookresearch/segment-anything.git -q")
from segment_anything import SamPredictor, sam_model_registry
import torch
ckpt = ensure_checkpoint(model_type, checkpoint)
sam = sam_model_registry[model_type](checkpoint=ckpt)
sam.to("cuda" if torch.cuda.is_available() else "cpu")
return SamPredictor(sam)
def segment(image_path, output_path, checkpoint=None, model_type="vit_b", points=None):
"""Single-subject segmentation using one or more hint points."""
from PIL import Image
predictor = _load_sam(model_type, checkpoint
The skill declares executable and network-capable behavior but does not define an explicit permission or allowed-tools scope. That creates an underconstrained execution boundary: an agent may invoke shell commands and fetch remote assets without a clearly documented security policy, increasing the chance of unintended code execution or network access in sensitive environments.
The description says to use the skill when users want to 'remove backgrounds, cut out objects, extract foreground subjects, or perform image segmentation' without defining narrower trigger constraints or exclusions. In a markdown skill file, this broad natural-language trigger guidance could match many ordinary image-editing requests and does not clarify when this skill should or should not be selected.
The script silently bootstraps both model artifacts and Python package code from remote locations without explicit upfront consent or safety messaging. While downloading a model may be expected for ML tooling, combining it with implicit package installation obscures side effects and can surprise users with network access and code execution in their environment.
The manifest describes using SAM to remove backgrounds and extract foreground subjects as transparent PNGs, which implies isolating a target subject. The segment_all path goes beyond that by scanning the whole image and exporting every distinct element it can find as separate transparent PNGs, which is a broader segmentation workflow than the stated single-subject/background-removal purpose.
No suspicious patterns detected.