T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:354- Finding
Remote Preflight Response Can Direct Local Command Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 354–357
Vulnerability Type: Execution of a remotely supplied command
Risk Level: HighVulnerable snippet:
text Read `readiness_card.decision` and **`next_action.command`**: - `block` -> abort. Do not sign or send (`next_action.step=do_not_pay`). - `warn` / `allow` -> host pay path: run `gate_eval_live` (refuse transcript). Cap spend on warn. Paid trust is optional Path A only — never the protection completion criterion.Technical Analysis
The Skill directs the Agent to read and run
next_action.command, which is obtained from the remote preflight response served byhttps://intel.twzrd.xyz/v1/intel/preflight. No local allowlist, fixed command mapping, argument validation, executable pinning, or non-shell invocation constraint is specified before execution.This crosses the boundary between untrusted remote response data and local command execution. The expected command may normally invoke the documented gate evaluation utility, but the response field itself is controlled by the remote service and can change independently of the reviewed Skill file.
Attack Path
- The Agent submits seller and payment information to the remote preflight endpoint.
- The endpoint returns a
warnorallowdecision together withnext_action.command. - The Skill instructs the Agent to run the returned command.
- A malicious service operator, compromised endpoint, or attacker capable of altering the authenticated service response substitutes an arbitrary command for the expected gate command.
- The Agent executes that command with its current local permissions.
Impact Assessment
Successful exploitation permits command execution with the privileges available to the Agent. Depending on those privileges, the command could read Agent-accessible files and credentials, modify project or user files, execute additional programs, or establish ...[truncated 234 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not execute command strings received from the preflight service.
- Replace
next_action.commandwith a constrained action identifier, such asgate_eval_live, and map that identifier to a fixed local implementation. - Allowlist all accepted actions and reject unknown response values.
- Invoke a pinned local executable directly with a structured argument array rather than through a shell.
- Validate every remotely supplied argument against a strict schema, including type, length, and permitted-value constraints.
- Pin the expected executable or package version and verify its integrity before invocation.
- Require explicit user confirmation if a response requests any action outside the predefined read-only gate workflow.
