T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:13- Finding
Automatic Execution of Remotely Retrieved GitHub Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13
Vulnerability Type: Remote payload retrieval and execution through an unverified dependency
Risk Level: HighVulnerable Code Snippet:
bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call rednote --url "https://www.xiaohongshu.com/explore/xxxx"Technical Analysis
The skill directs the agent to use
npx -yto download and execute a package from a personal GitHub repository. The-yoption suppresses the interactive installation confirmation, so invoking the skill can immediately execute remotely obtained package code.Although the dependency references the
v1.1.0Git tag, a tag is not equivalent to an integrity-verified artifact or an immutable commit hash. The reviewed project does not contain the dependency's implementation, a lockfile, a cryptographic integrity value, or vendored source through which its behavior could be verified. The effective code executed by the skill therefore exists outside the audited project.This is principally a remote payload retrieval and execution issue because skill invocation creates a direct channel from an external repository to local code execution. It also carries supply-chain risk: compromise of the repository, its maintainer account, the referenced tag, the dependency tree, or package lifecycle scripts could change the behavior executed by the command.
Attack Path
- An attacker compromises the external GitHub repository, a maintainer account, the referenced tag, or a transitive dependency used by the remote package.
- The attacker introduces malicious package code, a lifecycle script, or malicious CLI behavior.
- A user requests collection of a Rednote URL, causing the agent to follow the instruction in
SKILL.md. npx -yretrieves the external package without an installation confirmation.- npm lifecycle logic or the package CLI executes with the permissions and env ...[truncated 774 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not execute remotely fetched code directly with
npx -y. - Vendor the required CLI source into the reviewed project and audit all executable code and transitive dependencies.
- If external retrieval is unavoidable, pin the dependency to an immutable commit and verify a cryptographic digest before execution.
- Publish the package through a controlled registry with provenance attestations, signed releases, a lockfile, and integrity metadata.
- Disable or strictly control npm lifecycle scripts during installation.
- Run the CLI in a restricted sandbox with minimal filesystem access, an allowlisted network destination, no unnecessary environment variables, and a short-lived, least-privilege API credential.
- Require an explicit user confirmation before installation or execution and display the exact pinned source that will run.
- Do not execute remotely fetched code directly with
