T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:56- Finding
Unverified Remote Installer Is Executed Directly by Bash
- Content
View full analysis
= 3.3.3` required**: run `aliyun version` to verify. If not installed or the version is too low: - run `/bin/bash -c "$(curl -fsSL https://aliyuncli.alicdn.com/setup.sh)"` to install or update, or - run `aliyun upgrade` (available from CLI >= 3.3.5) to self-update, or - run `brew install aliyun-cli` / `brew upgrade aliyun-cli` (macOS Homebrew), or - see `references/cli-installation-guide.md` for full installation instructions. Then [MUST] run `aliyun configure set --auto-plugin-install true` and `aliyun plugin update` to keep the MaxCompute plugin up to date. ``` ### Technical Analysis The Skill instructs the agent to download a shell script from an external URL and pass the response directly to `/bin/bash`. The retrieved content is not pinned to a specific release, stored for inspection, or authenticated with a checksum or digital signature. Consequently, the effective code executed on the host can change after the Skill package has been audited. HTTPS protects transport under ordinary conditions but does not protect against compromise of the vendor endpoint, CDN, publishing process, or signing infrastructure. Direct execution also prevents the user from reviewing the downloaded payload before it runs. This behavior is not necessary for migration management itself. Installation can be performed through a verified, version-pinned package or through an explicitly reviewed administrative process. ### Attack Path 1. A user requests an MMS operation. 2. The Skill determines that Aliyun CLI is missing or outdated. 3. The agent runs the documented Bash command. 4. The external endpoint, CDN, DNS path, or publisher account supplies a modified `setup.sh`. 5. Bash immediately executes the modified payload with the privileges o ...[truncated 661 chars]- Remediation
View remediation
