T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:13- Finding
Runtime Retrieval and Execution of Externally Hosted Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call bilibili --url "https://www.bilibili.com/video/BV..."Technical Analysis
The skill instructs the agent to use
npx -yto retrieve and execute a package directly from an external GitHub repository. The package implementation is not included in the audited project, so its effective behavior cannot be verified from the local files.The reference selects a repository tag rather than a content-integrity-verified artifact or immutable commit hash. If the external repository, maintainer account, or referenced release becomes compromised, the downloaded package could be changed after this skill has been reviewed. The
-yoption suppresses the normal installation confirmation, allowing the remote package to execute during routine skill invocation.The executed process inherits the permissions and accessible environment of the agent process. In particular, the skill expects
HOTBEE_API_KEYto be present in the environment, so remotely supplied code may be able to read that credential in addition to accessing files and network resources available to the current user.Attack Path
- An attacker compromises the external GitHub repository, its maintainer account, or the referenced release/tag.
- The attacker causes the referenced package to contain malicious installation or runtime code.
- A user invokes the Bilibili collection skill.
- The documented
npx -ycommand downloads the externally controlled package without interactive confirmation. - The package executes with the current agent user's permissions.
- The malicious payload reads accessible environment variables, including
HOTBEE_API_KEY, and may access local files or make arbitrary outbound requests within the process's security boundaries.
I
...[truncated 640 chars]
- Remediation
View remediation
Remediation Suggestions
- Avoid executing code directly from a GitHub repository at runtime.
- Vendor the required implementation into the skill so it can be reviewed together with the project.
- If an external package is unavoidable, publish it through a trusted registry and pin an exact version using a lockfile with integrity hashes.
- Pin external source code to an immutable commit hash rather than a movable tag, and verify a trusted checksum or signature before execution.
- Remove automatic confirmation through
npx -ywhere feasible, and require explicit approval before installing or running externally retrieved code. - Execute the package in a restricted environment with minimal filesystem access, a limited environment-variable allowlist, and tightly controlled outbound network access.
- Ensure the child process receives only
HOTBEE_API_KEYwhen required rather than inheriting the complete parent environment.
