T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:327- Finding
Unverified Remote Dependency Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Baidu Netdisk skill is coherent overall, but it needs review because it can run unaudited installer scripts and upload broad agent memory files to cloud storage.
Install only after reviewing the missing scripts and the bdpan binary source yourself. Avoid memory backup unless you have inspected the listed memory files for secrets or private context and are comfortable storing them in Baidu Netdisk; prefer a sandboxed install and do not use the remote installer in sensitive environments without pinned integrity checks.
SKILL.md:327Unverified Remote Dependency Download and Execution
SKILL.md:343Overbroad Collection and Cloud Backup of Sensitive Agent State
SKILL.md:284Predictable Shared Temporary File in Incremental Synchronization
SKILL.md:273Unsafe Filename Handling in Batch and Incremental Processing Templates
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 清理日志
rm -f /tmp/bdpan-dl-<PID>.log
Agent执行大文件后台下载行为规范:
The skill directs uploading a broad set of Agent memory files and manifests to remote storage. These files can contain system prompts, user data, preferences, credentials, operational notes, or other high-value context; centralizing them in cloud storage significantly raises exposure in the event of account compromise, over-sharing, or retention beyond intended scope.
The trigger rules intentionally activate backup and restore operations for Agent memory even when the user does not mention cloud storage explicitly. This lowers the friction for shipping potentially sensitive memory artifacts off-host and makes accidental data disclosure more likely, especially because users may interpret '备份记忆' as a local-only action unless warned otherwise.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 启动后台下载
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# 启动后台下载
nohup bdpan download <远端路径> <本地路径> > /tmp/bdpan-dl-$$.log 2>&1 & echo $!
The install flow instructs the agent to run an installer script that downloads and executes code from a remote CDN, and even notes that no local SHA256 verification is performed. Although HTTPS is mentioned, the skill does not clearly warn that this results in execution of remote code on the user's system, creating supply-chain risk if the CDN content, transport, or upstream script is compromised.
The skill explicitly supports backing up and restoring Agent memory to Baidu Netdisk, including files like AGENTS.md, MEMORY.md, and memory/*.md, but it does not prominently warn that these may contain sensitive prompts, secrets, personal data, or operational context that will leave the local system. In a security-sensitive agent environment, transmitting comprehensive memory artifacts to cloud storage materially increases confidentiality risk and may expose credentials or sensitive internal state if the cloud account is compromised or shared.
No suspicious patterns detected.