T03 · Remote Payload Retrieval and Execution
- Location
references/README.md:244- Finding
Unverified Remote Installer Is Piped Directly Into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a broad automation runner that can direct an AI to create and run commands or code with your machine's permissions, with weak boundaries and unsafe optional setup guidance.
Install only if you intentionally want a high-authority automation skill that may run AI-generated shell commands or Python code. Use it in a disposable sandbox or restricted workspace, avoid confidential files and credentials, do not enable dangerous mode, do not follow the curl-to-sh installer pattern without independent verification, and review every generated command or script before execution.
references/README.md:244Unverified Remote Installer Is Piped Directly Into a Shell
scripts/universal_agent.py:1418Untrusted LLM and Bridge Responses Are Executed as Arbitrary Shell Commands
scripts/universal_agent.py:953Dynamically Generated Python Is Executed Without Isolation
scripts/universal_agent.py:1199Untrusted Persistent Memory Is Injected Into Future LLM Decision Context
scripts/universal_agent.py:564Sensitive Environment, Task, Memory, and Execution Data Can Be Sent to Arbitrary LLM Endpoints
The skill description prominently markets automated command/script execution but does not provide an upfront warning that it may alter files, system state, network resources, or hardware. Users and orchestrating agents may therefore treat it like a normal helper skill rather than a high-risk executor, increasing the likelihood of unsafe use.
The activation guidance is broad enough to match many ordinary requests such as 'help me do X automatically' or 'generate code and run it,' which can cause the skill to be selected in situations where users did not knowingly consent to autonomous execution. Because this skill generates and executes commands/scripts, overbroad invocation materially increases the chance of unintended code execution and system changes.
The keyword trigger '帮我做XX' is extremely vague and could match a wide range of everyday assistance requests. In a skill that can generate arbitrary scripts and execute shell commands, such vague matching creates a high risk of accidental invocation and execution without meaningful user awareness.
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Referenced artifact was not completely inspected
python scripts/universal_agent.py --run "task description"
Inline Simulation mode explicitly states that safety, retry, and memory protections do not apply, yet it lacks a corresponding high-visibility warning about the resulting risk to data and system integrity. This is especially dangerous because the surrounding documentation encourages agents to simulate the workflow using native capabilities, potentially bypassing even the script's limited guardrails.
This duplicate finding again points to documented destructive command examples, which are not themselves malicious content. The real security concern is that the skill's safety posture appears to center on matching known bad strings and then prompting, an approach that is easy to bypass with equivalent commands, scripting indirection, or platform-specific variants.
| Level | Examples | Handling |
|-------|----------|----------|
| 🔴 High | `rm -rf /`, `format C:` | **Forced confirmation required** |
| 🟡 Medium | `pip uninstall`, `sudo` | Warning prompt |
| 🟢 Low | `ls`, `cat`, `python script.py` | Direct execution |
This duplicate finding again points to documented destructive command examples, which are not themselves malicious content. The real security concern is that the skill's safety posture appears to center on matching known bad strings and then prompting, an approach that is easy to bypass with equivalent commands, scripting indirection, or platform-specific variants.
| Level | Examples | Handling |
|-------|----------|----------|
| 🔴 High | `rm -rf /`, `format C:` | **Forced confirmation required** |
| 🟡 Medium | `pip uninstall`, `sudo` | Warning prompt |
| 🟢 Low | `ls`, `cat`, `python script.py` | Direct execution |
The documentation includes an option to skip safety confirmations, which normalizes bypassing safeguards around command execution. Even though it is labeled 'not recommended,' exposing a documented path to disable confirmations materially lowers resistance to destructive or unintended actions in a high-risk execution skill.
# Optional: skip safety confirmations (not recommended)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 无需人工干预
### 🔒 安全机制
- 高危命令检测(rm -rf /, format C:, etc.)
- 危险操作强制确认
- 中危操作警告提示
- 可选的危险模式(跳过确认)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 无需人工干预
### 🔒 安全机制
- 高危命令检测(rm -rf /, format C:, etc.)
- 危险操作强制确认
- 中危操作警告提示
- 可选的危险模式(跳过确认)
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
- 无需人工干预
### 🔒 安全机制
- 高危命令检测(rm -rf /, format C:, etc.)
- 危险操作强制确认
- 中危操作警告提示
- 可选的危险模式(跳过确认)
The README recommends piping a remotely fetched install script directly into sh. That pattern removes inspection, signature verification, and integrity checks, so a compromised host, CDN, or man-in-the-middle position could lead to arbitrary code execution on the user's machine.
# 安装 Ollama
# Windows: https://ollama.ai/download
# Mac: brew install ollama
# Linux: curl -fsSL https://ollama.ai/install.sh | sh
# 运行本地模型
ollama run llama3 # 推荐,7B参数
The shell pipeline to sh is an explicit command-chaining pattern that executes unverified remote content immediately. In the context of a skill centered on automated command execution, normalizing this pattern materially increases the likelihood of unsafe operator behavior and remote code execution.
# 安装 Ollama
# Windows: https://ollama.ai/download
# Mac: brew install ollama
# Linux: curl -fsSL https://ollama.ai/install.sh | sh
# 运行本地模型
ollama run llama3 # 推荐,7B参数
This is the same underlying issue: subprocess.Popen is invoked with shell=True on dynamically generated command text. In a universal agent that advertises automatic command generation and execution, this creates a direct remote-code-execution primitive via prompt injection, malicious tasks, or compromised bridge inputs.
creationflags=subprocess.CREATE_NO_WINDOW if os.name == 'nt' else 0
)
else: # Linux/macOS
process = subprocess.Popen(
command,
shell=True,
stdout=subprocess.PIPE,
This is the same underlying issue: subprocess.Popen is invoked with shell=True on dynamically generated command text. In a universal agent that advertises automatic command generation and execution, this creates a direct remote-code-execution primitive via prompt injection, malicious tasks, or compromised bridge inputs.
creationflags=subprocess.CREATE_NO_WINDOW if os.name == 'nt' else 0
)
else: # Linux/macOS
process = subprocess.Popen(
command,
shell=True,
stdout=subprocess.PIPE,
The init method docstring begins at L1278 and never closes before assignments and component construction lines. The comments and surrounding class documentation describe a fully functional orchestrator that wires brain, executor, and memory together, but the shown code places that logic inside the docstring, contradicting the claimed operational behavior.
The agent sends user tasks, execution output, and serialized environment/context to external LLM APIs, including current directory, Python path, task history, variables, and learned knowledge, without an explicit warning or consent flow. This can expose sensitive local metadata, command output, secrets present in context, or proprietary data to third-party services.
The skill advertises capabilities spanning shell, file read/write, environment access, and network use, but it does not declare any explicit tool scope or permission boundaries. In a universal-agent context, that omission is dangerous because downstream agents may invoke it with broad ambient privileges, enabling generated code or commands to operate far beyond user intent.
The skill is explicitly designed to auto-execute LLM-generated commands or scripts, which delegates security-sensitive decisions to probabilistic model output. In context, this is especially dangerous because the skill also supports auto-fixing and retrying, increasing the likelihood that it will persist in attempting actions until something runs.
description: >
This skill should be used when the user needs to execute tasks through a complete
automated workflow: understand natural language intent, dynamically generate commands
or Python scripts, auto-execute them via shell, and summarize results. This is a
minimal universal agent implementation based on "LLM brain + command executor limbs"
architecture. Use this when users say things like "help me do X automatically",
"generate code and run it", "universal agent", "execute task end-to-end", or when
The skill explicitly frames its executor as able to 'Execute any command' and control software and hardware, indicating effectively unrestricted tool access. In a system driven by LLM-generated decisions, this creates a direct path from prompt interpretation errors or malicious input to arbitrary command execution, persistence, data loss, or physical-world effects.
│ Auto-generate code/command
↓
┌─────────────────┐
│ Command Executor │ Execute any command, control software & hardware
│ (Limbs) │
└───────┬─────────┘
│ Actual execution
Detected: suspicious.dynamic_code_execution