T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Remote Installation Script Executed Directly by a Shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 30
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash curl -fsSL https://raw.githubusercontent.com/agoodway/goodverify_cli/main/install.sh | shTechnical Analysis
The installation instructions download a shell script from the mutable
mainbranch of a personal GitHub repository and immediately pipe it tosh. The command does not pin an immutable release or commit, verify a cryptographic signature or checksum, save the script for inspection, or isolate its execution.The payload that executes can therefore change after this Skill has been reviewed. The repository owner—or an attacker who compromises the GitHub account, repository, branch, or release process—could replace
install.shwith arbitrary shell commands. Those commands would inherit the permissions, environment variables, filesystem access, and network access of the user running the installation.Installing the required CLI is relevant to the Skill's stated functionality. However, direct pipe-to-shell execution exceeds the minimum safe mechanism necessary to perform that installation because less risky, verifiable installation methods are available. The remote script was not included in the audited project, so its current contents and privilege behavior could not be assessed.
Attack Path
- An agent follows
SKILL.mdand determines that thegoodverifyCLI is not installed. - An attacker modifies
main/install.shafter compromising the repository or its maintainer account, or the repository owner publishes a malicious update. - The agent runs the documented
curl | shcommand. curlretrieves the current remote payload without pinning or integrity verification.- The shell executes the payload immediately, without a review or confirmation boundary.
- The payload performs arbitrary actions using the invoking user's privileges.
Impact Assessment
...[truncated 765 chars]
- An agent follows
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shinstallation instruction. - Publish versioned, reproducible CLI releases through a trusted package manager or release channel.
- Pin installation artifacts to an immutable version, release, or commit rather than the mutable
mainbranch. - Publish a SHA-256 checksum and preferably a cryptographic signature through an independently authenticated channel.
- Download the installer or binary to a local file, verify its integrity and authenticity, and allow inspection before execution.
- Require explicit user approval before installing or executing third-party software.
- Run installation with the least privileged account possible and do not request elevated privileges unless a documented operation strictly requires them.
- Document the files, directories, network endpoints, and configuration changes made by the installer.
- Prefer a transparent sequence such as:
bash curl -fL -o goodverify-install.sh "https://example.invalid/releases/v0.1.0/install.sh" echo "<expected-sha256> goodverify-install.sh" | sha256sum --check - less goodverify-install.sh sh goodverify-install.shThe placeholder URL and checksum must be replaced with a trusted immutable release artifact and its verified digest.
- Remove the direct
