T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:38- Finding
Mutable Remote Installation Script Is Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38 and 363
Vulnerability Type: Remote code retrieval and execution
Risk Level: CriticalVulnerable Code
bash # Automatic installation curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | shThe same command is repeated in the update instructions:
bash # Re-run the installation script curl -fsSL https://raw.githubusercontent.com/nashsu/opencli-rs/main/scripts/install.sh | shTechnical Analysis
The command downloads a shell script from the mutable
mainbranch of an external repository and passes it directly tosh. The downloaded script is not pinned to a reviewed commit, saved for inspection, or validated through a cryptographic checksum or signature.Consequently, the effective code executed by this Skill can change after the Skill package has been reviewed. HTTPS protects data in transit but does not protect against repository compromise, malicious maintainer changes, account takeover, or an altered upstream script.
Installation requires obtaining software, but pipe-to-shell execution is not the minimum privilege or safest mechanism necessary to accomplish that function.
Attack Path
- An attacker compromises the upstream repository or maintainer account, or otherwise modifies
main/scripts/install.sh. - A user or AI Agent follows the installation or update instructions.
curlretrieves the modified script.- The pipe sends the script directly to
shwithout review or integrity verification. - The script executes arbitrary commands with all privileges available to the invoking user.
- If the script invokes
sudoor is run from a privileged context, the compromise may extend to system-level access.
Impact Assessment
Successful exploitation provides arbitrary code execution as the invoking account. The payload could access user files, browser data, Agen ...[truncated 441 chars]
- An attacker compromises the upstream repository or maintainer account, or otherwise modifies
- Remediation
View remediation
Remediation Suggestions
- Remove all pipe-to-shell installation instructions.
- Pin the installer to an immutable, reviewed commit rather than
main. - Download the installer into a temporary file and require inspection before execution.
- Publish a SHA-256 checksum or signed manifest through an independently authenticated release channel.
- Verify the checksum or signature before execution.
- Prefer a reviewed installer shipped inside the Skill package.
- Run installation with ordinary user privileges and request elevation only for the exact filesystem operation that requires it.
- Document the precise files and configuration that installation will create or modify.
A safer pattern is:
bash version="REVIEWED_VERSION" curl -fL -o install.sh \ "https://raw.githubusercontent.com/nashsu/opencli-rs/REVIEWED_COMMIT/scripts/install.sh" printf '%s %s\n' "EXPECTED_SHA256" install.sh | sha256sum -c - less install.sh sh install.sh
