T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:37- Finding
Unpinned Remote Wallet Code Is Retrieved and Executed
- Content
View full analysis
/dev/null rm -rf /tmp/evm-wallet-tmp cd "$SKILL_DIR" && npm install fi ``` The update instructions provide another mutable execution path: ```bash node src/check-update.js --json ``` ```bash cd "$SKILL_DIR" && git pull && npm install ``` ### Technical Analysis The installation procedure clones the repository's mutable default branch and immediately runs `npm install`. Neither a reviewed commit hash nor a signed release, checksum, or other integrity constraint is specified. The update procedure similarly runs `git pull` and reinstalls dependencies without verifying the resulting source. This is a remote payload execution boundary: the effective wallet implementation can change after the Skill document has been reviewed. In addition, `npm install` may execute lifecycle scripts supplied by the downloaded project or its dependencies. The supplied audit artifact contains only `SKILL.md`; it does not include the downloaded wallet source, package manifest, or lockfile. Therefore, the behavior of wallet generation, private-key handling, RPC communication, transaction construction, and dependency installation cannot be independently verified from the audited artifact. ### Attack Path 1. An attacker compromises the upstream repository, a maintainer account, release process, or dependency chain. 2. The attacker adds malicious wallet code or an npm lifecycle script to the mutable branch or dependency graph. 3. An agent follows the documented bootstrap or update instructions. 4. `git clone` or `git pull` retrieves the attacker-c ...[truncated 1177 chars]- Remediation
View remediation
