T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:45- Finding
Externally Controlled Terminal Command Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45-48
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: MediumVulnerable Content:
markdown 1. Visit https://www.gemmamatch.com 2. Allow hardware detection (or enter specs manually) 3. Get your recommended model + run command 4. Copy the command and run it in your terminalTechnical Analysis
The skill directs users to obtain a terminal command from a mutable external website and execute it locally. The project does not define, validate, constrain, or pin the command that the website may return. Consequently, the effective command can change after this skill has been reviewed.
This creates a remote payload execution risk: if the external website, its hosting infrastructure, or its content-delivery path is compromised, an attacker could replace the expected model command with arbitrary shell instructions. Successful exploitation still requires the user to copy and execute the supplied command.
Attack Path
- An attacker compromises or otherwise gains control of
https://www.gemmamatch.comor its command-generation functionality. - The attacker changes the generated recommendation command to include a malicious payload.
- A user follows the instructions in
SKILL.mdand visits the website. - The website presents the attacker-controlled command as a legitimate model deployment command.
- The user copies and executes the command in a terminal.
- The payload runs with the permissions of that user.
Impact Assessment
A successful payload could execute arbitrary commands with the invoking user's privileges. Depending on those privileges and the generated command, this may permit installation of unwanted software, modification or deletion of user-accessible files, theft of accessible credentials or other local data, and further payload retrieval.
The reviewed project contains only
SKILL.md...[truncated 230 chars]- An attacker compromises or otherwise gains control of
- Remediation
View remediation
Remediation Suggestions
- Replace externally generated terminal instructions with fixed, reviewable command templates included directly in the skill.
- Strictly allowlist executable names, subcommands, flags, and argument formats if commands must be generated dynamically.
- Present commands as untrusted suggestions and require users to inspect them before execution.
- Never recommend piping downloaded content directly into a shell.
- Pin all referenced packages, models, and downloadable artifacts to trusted sources and verified versions.
- Publish cryptographic checksums or signatures for downloaded artifacts and instruct users to verify them before use.
- Avoid requesting elevated privileges; clearly warn users if a command requires administrator or root access.
- Make the website's command-generation source available for review and apply deployment integrity controls, restrictive content security policies, and strong administrative authentication.
