T03 · Remote Payload Retrieval and Execution
- Location
install.sh:8- Finding
Installer Downloads and Enables Unverified Remote Shell Scripts
- Content
View full analysis
Vulnerability Details
File Location:
install.sh:8, 14-22, 29-30
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Criticalbash SKILL_DIR="${SKILL_DIR:-./skills/voidborne}" BASE_URL="https://voidborne.org/skill" echo "🔹 Installing Voidborne skill..." echo "" mkdir -p "$SKILL_DIR/scripts" echo "Downloading SKILL.md..." curl -sf "$BASE_URL/SKILL.md" -o "$SKILL_DIR/SKILL.md" echo "Downloading scripts..." curl -sf "$BASE_URL/scripts/awaken.sh" -o "$SKILL_DIR/scripts/awaken.sh" curl -sf "$BASE_URL/scripts/status.sh" -o "$SKILL_DIR/scripts/status.sh" curl -sf "$BASE_URL/scripts/thought.sh" -o "$SKILL_DIR/scripts/thought.sh" chmod +x "$SKILL_DIR/scripts/"*.shThe installer then directs the user to execute a downloaded script:
bash echo "Next steps:" echo " cd $SKILL_DIR" echo " bash scripts/awaken.sh # Join the Awakened" echo " bash scripts/status.sh # Check status"Technical Analysis
The installation process does not install the scripts contained in the audited package. Instead, it downloads replacement shell scripts from mutable endpoints under
https://voidborne.org/skill.HTTPS protects data in transit but does not establish that the downloaded scripts are identical to the audited versions. The installer performs no cryptographic hash comparison, digital-signature verification, immutable version pinning, or other content-integrity check. It subsequently grants the downloaded files executable permissions and directs the user to run them.
Consequently, control or compromise of the remote domain, web server, TLS termination infrastructure, hosting account, or deployment pipeline would allow the effective skill payload to be changed after review.
Attack Path
- An attacker compromises the remote hosting infrastructure or otherwise gains the ability to alter a script beneath
https://voidborne.org/skill/scripts/. - The at ...[truncated 955 chars]
- An attacker compromises the remote hosting infrastructure or otherwise gains the ability to alter a script beneath
- Remediation
View remediation
Remediation Suggestions
- Install the shell scripts directly from the reviewed package rather than downloading mutable replacements.
- If remote retrieval is necessary, publish immutable, versioned artifacts.
- Pin an expected SHA-256 or stronger digest in the installer and verify every downloaded file before granting execution permission.
- Prefer signed release manifests and validate signatures against a trusted public key embedded in the reviewed package.
- Download into a private temporary directory, verify all artifacts, and only then move them into the final installation directory.
- Abort installation and remove downloaded files if any verification fails.
- Apply restrictive file permissions and avoid encouraging execution until verification has completed successfully.
