External Script Fetching
- Category
- Supply Chain
- Confidence
- 90% confidence
- Finding
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- Content
md **Critical(任一命中 = DANGER,直接淘汰)**: - 读取 `~/.ssh`、`~/.aws`、`~/.env`、credentials 文件、浏览器 Cookie/配置数据 - `curl ... | bash`、`wget ... | sh` 类下载即执行 - 无防护的破坏性命令:`rm -rf`、`sudo`、大范围 `chmod/chown` - 明显 prompt injection:"ignore previous instructions"、"send/upload the contents of ..."、诱导把本地数据外发 - 长 base64 串、混淆或加密的脚本内容(读不懂 = 无法审计)
