T03 · Remote Payload Retrieval and Execution
- Location
- Save content to temp file, then compute SHA256: shasum -a 256 <temp_file> | awk '{print $1}' - Compare with manifest checksum (strip "sha256:" prefix) - If mismatch: ABORT entire update. - If file extension is `.js` AND the local file already exists at SKILL_DIR/<file>: → Show to user: "⚠️ Code module update: <file> (LOCAL_VERSION → manifest.version). Allow? [Y/n]" → If user declines: skip this file, continue with remaining files - If match: save to SKILL_DIR/.skill ...[truncated 3886 chars]:19- Finding
Automatic Retrieval and Installation of Mutable Remote Skill Payloads
- Content
View full analysis
LOCAL_VERSION: a. For each file in manifest.files: - Download: curl -sf -H "User-Agent: bybit-skill/1.5.8" https://raw.githubusercontent.com/bybit-exchange/skills/main/ - Save content to temp file, then compute SHA256: shasum -a 256 | awk '{print $1}' - Compare with manifest checksum (strip "sha256:" prefix) - If mismatch: ABORT entire update. - If file extension is `.js` AND the local file already exists at SKILL_DIR/: → Show to user: "⚠️ Code module update: (LOCAL_VERSION → manifest.version). Allow? [Y/n]" → If user declines: skip this file, continue with remaining files - If match: save to SKILL_DIR/.skill-update-tmp/ b. ALL files verified → move from temp to SKILL_DIR: - For each file: mkdir -p parent dir, then mv .skill-update-tmp/ SKILL_DIR/ - rm -rf SKILL_DIR/.skill-update-tmp/ ``` ```text ### How to load a module 1. Identify which module(s) the user's request needs from the table below 2. If the module has NOT been loaded in this session: a. Ensure manifest is available: - If cached from Auto Update: reuse it - Otherwise: MANIFEST = curl -sf -H "User-Agent: bybit-skill/1.5.8" https://api.bybit.com/skill ...[truncated 3205 chars]- Remediation
View remediation
