T03 · Remote Payload Retrieval and Execution
- Location
scripts/audit.py:318- Finding
Automatic Execution of an Unpinned Remote Installation Script
- Content
View full analysis
str: """Return path to trivy, installing it if not found.""" path = shutil.which("trivy") if path: return path print("⚠️ Trivy not found. Installing...") if sys.platform == "darwin": subprocess.run(["brew", "install", "trivy"], check=True) else: subprocess.run( "curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b /usr/local/bin", shell=True, check=True, ) return shutil.which("trivy") or "trivy" ``` ### Technical Analysis When Trivy is unavailable on a non-macOS system, the Skill automatically downloads an installation script from the mutable `main` branch of an external GitHub repository and pipes the response directly into `sh`. The downloaded content is not pinned to a release or commit, inspected, checksum-verified, or authenticated with a cryptographic signature. Consequently, the effective code executed by the reviewed Skill can change after publication. Compromise of the upstream repository, GitHub account, release process, or delivery path could cause arbitrary attacker-controlled commands to run during an ordinary audit. Using `shell=True` and a `curl | sh` pipeline eliminates the opportunity to review or validate the downloaded file before execution. Installing into `/usr/local/bin` also exceeds the minimum privilege required to produce a license report. The operation will ordinarily fail without suitable write permission, but it could modify a system-wide executable directory if the Skill is run by a privileged user or in an environment where that directory is writable. ### Attack Path 1. A user invokes `scripts/audit.py` on a non-macOS host. 2. `ensure_trivy()` determines that no `triv ...[truncated 1178 chars]- Remediation
View remediation
