T03 · Remote Payload Retrieval and Execution
- Location
setup.sh:169- Finding
Unverified Remote Installer Piped Directly to a Shell
- Content
View full analysis
/dev/null; then ok "uv found (fast package installer)" else info "uv not found — will use pip (slower installs)" info "Install uv for faster setup: curl -LsSf https://astral.sh/uv/install.sh | sh" fi ``` ### Technical Analysis The setup script recommends downloading mutable content from an external URL and piping it directly into `sh`. Although the project only prints this command rather than executing it automatically, it presents the command as an installation instruction likely to be copied and run by users. The downloaded script is not pinned to a reviewed version and is not validated using a cryptographic checksum or signature. Consequently, the code ultimately executed can differ from the code that existed when this Skill was audited. HTTPS protects the connection in transit but does not protect against compromise of the hosting service, publication pipeline, domain, or vendor account. Installing `uv` is optional because the setup already falls back to `pip`. Direct remote shell execution therefore exceeds the minimum behavior necessary for transcription. ### Attack Path 1. An attacker compromises the remote installation endpoint, its publication pipeline, or another component trusted to serve `https://astral.sh/uv/install.sh`. 2. The attacker replaces the expected installer with a malicious shell payload. 3. A user runs `setup.sh` and receives the displayed `curl | sh` recommendation. 4. The user copies and executes the recommended command. 5. `curl` retrieves the current attacker-controlled payload and passes it directly to `sh`. 6. The payload executes with all permissions of the user who invoked the command. ### Impact Assessment A successful attack obtains arbitrary command execution under the invokin ...[truncated 316 chars]- Remediation
View remediation
