T03 · Remote Payload Retrieval and Execution
- Location
references/frontend_dependency_installation/node_environment.md:55- Finding
Unverified Remote Script Is Piped Directly into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This code-review skill is mostly coherent, but it gives the agent broad side-effecting authority such as installing untrusted dependencies, creating SSH keys, deleting local repo changes, and pushing commits without clear per-action approval.
Install only if you are comfortable with a code-review agent that can run package managers, modify review output folders, create or use SSH authentication, and push commits. Prefer read-only credentials, disposable clones or containers, no automatic dependency scripts, no curl-to-shell installers, and explicit confirmation before any git reset, clean, commit, push, or SSH-key creation.
references/frontend_dependency_installation/node_environment.md:55Unverified Remote Script Is Piped Directly into a Shell
references/python_dependency_installation/project_dependencies.md:24Audited Repositories Can Execute Code Through Dependency Installation Hooks
references/repository_access.md:80Repository Synchronization Permanently Deletes Local Work
references/report_delivery.md:12Code Review Workflow Automatically Modifies and Pushes Remote Repositories
references/repository_access.md:11Skill Automatically Creates a Persistent Passphrase-Free SSH Identity
references/installation.md:213Mutable Unsigned Skill Archive Can Replace Agent Instructions
curl https://get.volta.sh | bash fetches a remote script and immediately executes it, which is a classic supply-chain hazard. If the remote endpoint, TLS trust chain, network path, or hosting account is compromised, the reviewer environment can be fully compromised with arbitrary code execution.
curl https://get.volta.sh | bash
The | bash chaining pattern removes any inspection boundary between download and execution, turning a documentation step into direct arbitrary code execution. In the context of an automated code-review skill that may operate on remote infrastructure, this is especially dangerous because it can convert a routine setup step into full environment takeover.
curl https://get.volta.sh | bash
The document expands a code-review skill into repository mutation by automatically editing .gitignore and then committing and pushing that change upstream. For a review-only capability, this is dangerous because it authorizes write actions to a remote repository that can alter project history, trigger CI/CD, and make persistent changes unrelated to analysis.
Embedding remote git commit/git push instructions in a code-review skill gives the skill write-back capability that is not necessary for its stated purpose. In the context of an automated agent, this creates a path for unauthorized repository changes, accidental policy violations, or abuse of available Git credentials.
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
mkdir -p download_skills curl -L -o download_skills/code-review.zip "https://clawhub.ai/api/skills/download?slug=code-review&ownerHandle=tinycen" unzip download_skills/code-review.zip -d download_skills/code-review rm download_skills/code-review.zip
2. **移动到对应技能目录**:
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
mkdir -p download_skills curl -L -o download_skills/code-review.zip "https://clawhub.ai/api/skills/download?slug=code-review&ownerHandle=tinycen" unzip download_skills/code-review.zip -d download_skills/code-review rm download_skills/code-review.zip
2. **移动到对应技能目录**:
The skill is described as a code-review tool, but this document authorizes mutating repository state by editing .gitignore, committing, and pushing to the remote. That exceeds a read-only review function and can cause unauthorized writes to user repositories, especially if triggered automatically in remote review flows.
Automatically executing git push grants the skill code-hosting write capability that is not necessary for code-quality analysis. If misused or triggered unexpectedly, it can alter remote repositories, create audit noise, and potentially introduce policy-violating changes under the user's identity or automation credentials.
The skill directs the agent to automatically commit and push generated artifacts to a remote repository, including retry logic, without a clear user-facing confirmation immediately before the remote write. This is a high-risk action because it can publish sensitive review content, trigger CI/CD workflows, mutate audit history, and exfiltrate repository-derived data to external infrastructure.
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:
1. **检查本地是否存在 SSH 密钥**
- 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
- 若存在:进入步骤 2
- 若不存在:进入步骤 3(自动生成)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:
1. **检查本地是否存在 SSH 密钥**
- 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
- 若存在:进入步骤 2
- 若不存在:进入步骤 3(自动生成)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:
1. **检查本地是否存在 SSH 密钥**
- 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
- 若存在:进入步骤 2
- 若不存在:进入步骤 3(自动生成)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:
1. **检查本地是否存在 SSH 密钥**
- 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
- 若存在:进入步骤 2
- 若不存在:进入步骤 3(自动生成)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
首次从 GitHub 拉取/推送代码前,必须执行以下检查流程,确保 SSH 认证可用:
1. **检查本地是否存在 SSH 密钥**
- 检查默认密钥路径:`~/.ssh/id_ed25519.pub` 或 `~/.ssh/id_rsa.pub`
- 若存在:进入步骤 2
- 若不存在:进入步骤 3(自动生成)
Automatically creating an SSH keypair on the host modifies authentication state and establishes a durable credential without strong necessity for code review. Even though the private key is not explicitly exfiltrated, generating new credentials from within the skill creates persistence and broadens the trust boundary of the tool.
3. **自动生成 SSH 密钥(无密钥时)**
- 生成 ed25519 密钥对:
```bash
ssh-keygen -t ed25519 -C "code-review@automation" -f ~/.ssh/id_ed25519 -N ""
```
- 读取公钥内容:`cat ~/.ssh/id_ed25519.pub`
- **将公钥内容发送给用户**,并提示:
git reset --hard is a destructive command that discards local tracked changes with no recovery path in normal workflows. In a code-review skill context, embedding this as a default update step creates significant risk of accidental loss and can be abused if the agent is induced to run it in an unintended repository.
当本地已存在目标仓库时:
1. 进入该仓库目录
2. 执行 `git reset --hard HEAD` 重置本地修改
3. 执行 `git clean -fd` 清理未跟踪文件
4. 执行 `git pull origin main` 拉取最新代码
The command block operationalizes a destructive reset as copy-pastable guidance, making unsafe execution more likely. Because the skill is for code review rather than repo administration, normalizing this parameter use violates least privilege and increases the blast radius of mistakes.
cd <workspace>/repos/<域名>/<仓库名>
git reset --hard HEAD
git clean -fd
git pull origin main
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- **检查项**:元数据是否完整
#### 环境文件
- **检查项**:.env 文件是否被 .gitignore 排除
- **检查项**:环境变量模板文件(.env.example)是否提供
#### 其他配置文件
The workflow explicitly instructs scheduled runs to discard uncommitted local changes before proceeding, but provides no user warning, opt-in requirement, backup step, or safety guard. In a code-review skill that operates on local repositories, this can destroy user work or unrelated in-progress changes and is especially risky because scheduled execution may happen without interactive confirmation.
The workflow includes saving reports plus attempting remote git commit and push, but does not require a clear warning or approval for repository mutation and outbound publication. In skill context, this is especially dangerous because a code-review tool is expected to inspect code, not silently publish changes or potentially leak findings to a remote origin.
This is a true tool-abuse risk because the workflow prescribes dangerous git commands (git reset --hard and git clean -fd) based only on repository state, without validating that the target path is a dedicated disposable checkout or obtaining approval. In the context of a code-review skill that clones and reuses local repositories, this is more dangerous because an attacker or misconfiguration could steer the workflow toward a sensitive working tree and cause irreversible data loss during automated execution.
- 进入本地绝对路径。
- 检查本地仓库是否有未提交的修改(`git status --short`)。
- 若有修改:自动执行 `git reset --hard HEAD` 与 `git clean -fd` 撤销所有本地修改。
- 检查仓库是否存在 tag 标签:
- 存在 tag:获取本地最新 tag,进入步骤 3。
- 不存在 tag:获取本地 HEAD,进入步骤 4。
The FAQ recommends automatically checking or generating SSH keys and sending them to the user, but gives no warning about handling private key material, passphrases, destination validation, or safer alternatives. In a code-review skill that interacts with repositories, credential-generation automation is sensitive and can expose authentication secrets or encourage insecure key management workflows.
The skill description includes broad trigger phrases such as '检查代码质量', '审查报告', and instructions to use the skill whenever the user mentions using the skill itself. These can overlap with ordinary discussion or high-level requests, causing the agent to invoke a workflow that may clone repositories or modify local files without sufficiently explicit user intent.
The skill explicitly supports cloning repositories, installing dependencies, generating reports, and automatically moving files between directories, but the entry document does not present clear user-facing warnings or consent gates for these side effects. In an agent setting, this increases the risk of unexpected network access, filesystem changes, or execution of untrusted project setup steps when a user intended only a discussion or review plan.
SQP-3 applies to all file types and flags language/locale policy violations. This markdown skill guidance forces a specific language for all readers, and the file does not mention that Chinese is optional, user-selected, or required for a region-specific purpose.
No suspicious patterns detected.