T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:12- Finding
Automatic Retrieval and Execution of Mutable Remote Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:12-16
Additional Locations:references/api.md:40-48
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighCode Snippet:
markdown Use the package CLI: ```bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --text "解析这个视频的播放量和评论 https://v.douyin.com/xxxx/"text Additional documented execution examples: ```bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --dry-run --text "解析这个视频的播放量和评论 https://v.douyin.com/xxxx/"bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call douyin --dry-run --text "分析这个达人主页的作品和粉丝画像 https://www.douyin.com/user/xxxx"Technical Analysis
The skill instructs the agent to use
npx -yto retrieve and execute a package directly from an external GitHub repository. The-yoption suppresses the interactive installation confirmation. The repository contents and executable implementation are not included in the audited project, so the actual package code, lifecycle scripts, transitive dependencies, and runtime behavior cannot be verified from this artifact.The reference
#v1.1.0identifies a Git tag rather than an immutable, locally verified artifact. Unless external controls guarantee that the tag cannot be moved and that the downloaded archive is integrity-checked, the effective payload may change after this skill has been reviewed. The remote process also executes in the agent's local security context and may inherit environment variables, includingHOTBEE_API_KEY.Attack Path
- An attacker compromises the referenced GitHub account, repository, release process, or a transitive dependency.
- The attacker modifies the content resolved by the
v1.1.0reference or causes malicious dependency code to be installed. - A user invokes the skill for a Douyin data request.
- The agent runs ...[truncated 836 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not automatically execute code directly from a mutable Git repository.
- Vendor the CLI source into the reviewed project or distribute it through a controlled registry with an audited release process.
- Pin the dependency to an immutable commit or content-addressed artifact and verify a trusted cryptographic digest before execution.
- Generate and verify a lockfile for all transitive dependencies.
- Disable package lifecycle scripts unless they are explicitly required and audited.
- Remove
-yso unexpected installation requires explicit approval. - Execute the CLI in a sandbox with a minimal environment, restricted filesystem access, and outbound-network access limited to approved API domains.
- Provide
HOTBEE_API_KEYonly to the subprocess and endpoint that require it rather than exposing the complete parent environment. - Audit the referenced CLI and all transitive dependencies before treating this skill as trusted.
