T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:20- Finding
Unverified Remote Installation Script Is Piped Directly into Bash
- Content
View full analysis
= 3.3.3 required** > Run `aliyun version` to verify >= 3.3.3. If not installed or version too low, > run `curl -fsSL https://aliyuncli.alicdn.com/setup.sh | bash` to update, > or see `references/cli-installation-guide.md` for installation instructions. **Pre-check: Aliyun CLI plugin update required** > [MUST] run `aliyun configure set --auto-plugin-install true` to enable automatic plugin installation. > [MUST] run `aliyun plugin update` to ensure that any existing plugins are always up-to-date. ```bash curl -fsSL --connect-timeout 4 --max-time 120 https://aliyuncli.alicdn.com/setup.sh | bash aliyun version ``` ``` ### Technical Analysis The installation command sends content retrieved from an external URL directly to Bash. There is no intermediate review, version pinning, cryptographic signature verification, or checksum validation. The effective code executed by the Skill can therefore change after the Skill package has been reviewed. HTTPS protects the connection in transit but does not establish that the mutable script remains safe. Compromise of the hosting infrastructure, CDN, publishing account, DNS/TLS trust path, or upstream release process could replace the script with arbitrary shell commands. The standalone command at line 30 also appears unconditional, even though the preceding text states installation is only necessary when the CLI is absent or below version 3.3.3. Installation and arbitrary shell execution are not inherently required to perform the declared read-only Hologres queries when a suitable CLI is already available. ### Attack Path 1. A user or Agent loads the Skill to list or inspect Hologres instances. 2. The Skill instructs the Agent to execute the mandatory installation sequence. 3. An attack ...[truncated 1251 chars]- Remediation
View remediation
