T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:29- Finding
Unverified Remote Installer Piped Directly into a Shell
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:29references/troubleshooting.md:5
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
SKILL.md:29bash curl -sSL https://raw.githubusercontent.com/Polymarket/polymarket-cli/main/install.sh | shreferences/troubleshooting.md:5text - 确认安装:`brew install polymarket` 或 `curl -sSL ... | sh`Technical Analysis
The primary installation procedure downloads a shell script from the mutable
mainbranch of an external GitHub repository and immediately passes its contents tosh. The downloaded content is not pinned to a release or commit and is not authenticated through a cryptographic signature or verified against a trusted checksum. It is also not saved for inspection before execution.Consequently, the effective code executed by this Skill can change after the Skill itself has been reviewed. Compromise of the upstream repository, maintainer account, branch, or release workflow could turn the installer into an arbitrary-code delivery mechanism. The abbreviated troubleshooting instruction reinforces the same unsafe installation pattern, although its ellipsis means that particular example is not independently executable without substitution.
This behavior exceeds the minimum privileges required to install or use the declared CLI. Installation requires placing a known executable in an appropriate location; it does not require granting an unreviewed, mutable network response unrestricted shell execution. The remote script runs with all permissions available to the invoking Agent or user.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or another mechanism capable of modifying
install.shon themainbranch. - The attacker changes the installer to include malicious shell commands.
- An Agent follows
SKILL.mdafter determining that the `p ...[truncated 1528 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove every
curl | shinstallation recommendation, including the abbreviated troubleshooting example. - Pin installation artifacts to a specific reviewed release version or immutable commit rather than the mutable
mainbranch. - Download the artifact without executing it immediately:
bash curl --fail --show-error --location --output polymarket-installer.sh \ https://example.invalid/path/to/pinned/version/install.sh - Verify the downloaded artifact against a checksum obtained through a trusted, independently authenticated release channel:
bash echo '<EXPECTED_SHA256> polymarket-installer.sh' | sha256sum --check - - Prefer cryptographic signature verification when the upstream project publishes signed release artifacts.
- Allow inspection of the downloaded script before execution and obtain explicit user approval.
- Run installation with the least-privileged account possible. Do not use
sudounless a reviewed installation step demonstrably requires it. - Prefer a pinned package-manager release where package provenance and integrity verification are available.
- Update
references/troubleshooting.md:5to refer only to the hardened, pinned installation procedure rather than encouraging direct remote-shell execution.
- Remove every
