T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:35- Finding
Unpinned Remote Repository Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35–39
Vulnerability Type: Mutable external code retrieval and execution
Risk Level: Highbash git clone https://github.com/ssrajadh/sentrysearch.git cd sentrysearch uv syncTechnical Analysis
The setup instructions clone the current default branch of an external Git repository without specifying an immutable commit hash or verified release tag. They then run
uv sync, which processes the remotely supplied project configuration and installs its dependencies.Consequently, the code installed by users can differ from the code that existed when this Skill was audited. The Skill package contains only
SKILL.md; it does not include the application source, a locally reviewable lockfile, integrity hashes, or signature-verification instructions. A malicious or compromised upstream revision can therefore become the effective payload without requiring any change to the audited Skill.Although
uv syncalso creates dependency supply-chain exposure, the primary issue is remote payload retrieval: the mutable repository determines which application code and dependency configuration are installed.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
- The attacker adds malicious application code or modifies dependency declarations to reference a malicious component.
- A user follows the documented setup procedure and clones the mutable default branch.
- The user runs
uv sync, causing the attacker-controlled project and dependencies to be installed. - The malicious payload executes during installation or when the user subsequently invokes
sentrysearch. - The payload operates with the invoking user's privileges and may access resources available to that user.
Impact Assessment
Successful exploitation can result in arbitrary code execution under the account running the installation or application. Access ...[truncated 557 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable clone instruction with an immutable, reviewed commit:
bash git clone https://github.com/ssrajadh/sentrysearch.git cd sentrysearch git checkout --detach <reviewed-full-commit-hash> - Prefer a signed release artifact and document verification of its signature and cryptographic checksum before installation.
- Include a reviewed dependency lockfile and require locked or frozen installation so dependency resolution cannot silently select newer versions.
- Verify package hashes where supported and reject dependencies that do not match approved integrity metadata.
- Review the pinned application source, build configuration, installation hooks, and complete transitive dependency graph.
- Run installation and video processing in a sandbox or dedicated low-privilege environment with access limited to explicitly selected footage and output directories.
- Supply the Gemini credential only at runtime, restrict its API permissions and quota where possible, and avoid exposing unrelated credentials to the process.
- Establish a controlled update procedure in which new upstream revisions are reviewed and assigned a new verified commit or release before users are instructed to upgrade.
- Replace the mutable clone instruction with an immutable, reviewed commit:
