T03 · Remote Payload Retrieval and Execution
- Location
subskills/exec-agent/env_checker.py:160- Finding
Automatic Retrieval and Shell Execution of a Mutable Remote Installer
- Content
View full analysis
str: """Get installation command for missing dependency.""" install_commands = { 'uv': 'brew install uv', 'python': 'brew install python', 'python3': 'brew install python', 'node': 'brew install node', 'npm': 'brew install node', 'yarn': 'npm install -g yarn', 'go': 'brew install go', 'cargo': 'curl --proto \'=https\' --tlsv1.2 -sSf https://sh.rustup.rs | sh', 'java': 'brew install openjdk', 'ruby': 'brew install ruby', 'php': 'brew install php' } return install_commands.get(command, None) ``` ```python install_cmd = self.get_installation_command(command) if not install_cmd: print(f" ✗ No automatic installation available for {command}") return False print(f" Installing {command}...") print(f" Command: {install_cmd}") try: result = subprocess.run( install_cmd, shell=True, capture_output=True, text=True, timeout=300 ) ``` The behavior is enabled by the default configuration: ```yaml execution: timeout_per_task: 300 max_retries: 2 parallel_execution: false auto_install_deps: true ``` The orchestrator propagates that setting automatically: ```python if exec_config.get('auto_install_deps', False): cmd.append('--auto-install') print(" → Auto-install dependencies enabled") ``` ### Technical Analysis When `cargo` is considered a required but missing command, the dependency checker downloads the current response from `https://sh.rustup.rs` and immediately pipes it into a shell. The payload is neither pinned to a specific immutable version nor verified using a cryptogra ...[truncated 1860 chars]- Remediation
View remediation
