T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:20- Finding
Unverified remote installer is piped directly into a shell
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20-39
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighThe installation instructions execute a remotely retrieved, mutable shell script without pinning its version, verifying a checksum, or allowing the user to inspect it first.
bash **Method 1: Use the official installation script** curl -LsSf https://astral.sh/uv/install.sh | sh **Method 2: Use a domestic mirror if the official download fails** export UV_INDEX_URL="https://pypi.tuna.tsinghua.edu.cn/simple" curl -LsSf https://astral.sh/uv/install.sh | sh export UV_INDEX_URL="https://mirrors.aliyun.com/pypi/simple/" curl -LsSf https://astral.sh/uv/install.sh | shTechnical Analysis
Piping
curloutput directly intoshcreates a remote code-execution channel. The executed payload is not part of the reviewed Skill package and can change after this audit. HTTPS protects transport under normal conditions but does not establish that the retrieved script is immutable or safe. A compromised upstream server, publishing process, domain, certificate trust path, or delivery infrastructure could replace the installer.The
-foption only rejects HTTP failure responses; it does not validate the content against a trusted digest or signature. The-soption also suppresses progress and some diagnostic information, reducing visibility during installation.Installing
uvis related to the Skill's dependency requirements, but arbitrary remote shell execution is broader than the minimum privilege needed to install a known tool. The script executes with all permissions of the user running the instructions.Attack Path
- An attacker compromises the installer host, its deployment pipeline, or another trusted part of the delivery path.
- The attacker modifies
https://astral.sh/uv/install.shto include malicious shell commands. - A user or agent follows the Skill instru ...[truncated 756 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not pipe network content directly into a shell.
- Prefer installation through an operating-system package manager or another trusted, auditable distribution mechanism.
- If the upstream installer must be used, download a versioned artifact first, verify a publisher-provided cryptographic signature or a pinned SHA-256 digest, inspect it, and only then execute it.
- Pin the installer or release version rather than relying on the mutable
install.shendpoint. - Run installation as an unprivileged user and explicitly warn users not to use
sudounless a documented step strictly requires it. - Avoid presenting alternate package indexes without documenting their trust implications.
- Example hardened workflow:
bash curl --proto '=https' --tlsv1.2 -fLo uv-installer.sh \ 'https://example.invalid/pinned-version/uv-installer.sh' echo 'PINNED_SHA256 uv-installer.sh' | sha256sum --check - sh uv-installer.sh rm -f uv-installer.shThe URL and digest must be replaced with an authentic, version-specific release artifact and checksum obtained through a trusted channel.
