T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:14- Finding
Execution of an Unverified Remote Installation Script
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 14
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash curl -fsSL https://raw.githubusercontent.com/shijianzhong/multi-platform-articles/main/scripts/install.sh | shTechnical Analysis
The installation instruction downloads a shell script from a personal GitHub repository and immediately pipes it into
sh. The URL references the mutablemainbranch rather than an immutable release or commit. Consequently, the effective code executed by users can change after the Skill has been reviewed.No version pinning, cryptographic checksum, signature verification, or inspection step is provided. The
-fand-soptions also reduce diagnostic visibility. Although the documentation states that the installer placesmpain~/.local/bin, that statement does not technically constrain the remote script: it executes with all privileges and filesystem access available to the invoking user.Direct remote execution is not required for the declared Markdown conversion and publishing functionality. A versioned, integrity-verified installation mechanism would provide the dependency without granting mutable remote content an immediate shell execution channel.
Attack Path
- A user requests article formatting or publication.
- The agent determines that the
mpacommand is unavailable. - Following
SKILL.md, the agent directs the user to execute the documented installation pipeline. - The command retrieves the current
install.shcontent from the repository's mutablemainbranch. - The downloaded content is passed directly to
shwithout integrity verification or review. - If the repository, maintainer account, or delivery path supplies malicious content, arbitrary commands execute under the user's account.
- A malicious installer could alter the installed
mpaexecutable, access user d ...[truncated 864 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstallation workflow. - Distribute
mpathrough a reputable package registry using a fixed, documented version. - If a standalone installer is necessary, reference an immutable release asset or commit rather than the mutable
mainbranch. - Publish and verify a SHA-256 checksum or cryptographic signature before execution.
- Separate download from execution so users can inspect the script:
bash curl -fSLo install-mpa.sh "https://example.invalid/immutable/version/install.sh" echo "<expected-sha256> install-mpa.sh" | sha256sum -c - less install-mpa.sh sh install-mpa.sh - Document all files, network requests, and configuration changes performed by the installer.
- Ensure installation is restricted to the user's application directory and does not request elevated privileges unless a clearly justified operation requires them.
- Pin and verify any artifacts or dependencies subsequently downloaded by the installer.
- Remove the
