Back to skill

Security audit

Agent Hand

Security checks for vulnerabilities and agentic risk

Overview

The skill describes a legitimate AI-session dashboard, but its install and hook setup ask users to run mutable remote code and make broad persistent changes without enough scoping or verification.

Review this carefully before installing. Do not run the one-line installer unless you trust the upstream repository and maintainer; prefer downloading a pinned release or installer, inspecting it, and verifying a checksum first. Also check what `agent-hand hooks install` changes in your Claude, Cursor, Codex, Gemini, and other agent configurations, and confirm there is a clear uninstall path.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:19
Finding

Unverified Remote Installer Executed Directly Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 19
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

bash
curl -fsSL https://raw.githubusercontent.com/weykon/agent-hand/master/install.sh | bash

Technical Analysis

The installation command retrieves install.sh from the mutable master branch of an external GitHub repository and pipes the response directly into Bash. The downloaded content is executed without being displayed, reviewed, pinned to an immutable commit or release, or validated with a cryptographic checksum or signature.

Because the installer is not included in the audited project, its behavior cannot be verified from the available artifact. The effective payload can also change after this Skill has been reviewed. Compromise of the upstream repository, its maintainer account, or its delivery path could therefore turn the documented installation command into an arbitrary-code execution channel.

Direct execution is not necessary merely to provide installation instructions and exceeds the minimum-risk approach appropriate for the declared functionality.

Attack Path

  1. An attacker compromises the upstream repository or maintainer account, or otherwise gains the ability to modify master/install.sh.
  2. The attacker replaces or modifies the installer to include malicious shell commands.
  3. A user follows the installation command documented in SKILL.md.
  4. curl downloads the current attacker-controlled script.
  5. The shell immediately executes the response without integrity verification or user inspection.
  6. The payload performs arbitrary actions with the privileges of the user running the command.

Impact Assessment

Successful exploitation permits arbitrary command execution under the installing user's account. The payload could read or modify files accessible to that account, access developer credentials and agent configuration, install o ...[truncated 397 chars]

Remediation
View remediation

Remediation Suggestions

  • Do not pipe network responses directly into a shell.
  • Publish versioned release artifacts and reference an immutable release version or commit rather than the mutable master branch.
  • Provide a cryptographic SHA-256 checksum through an independently protected channel and require users to verify it before execution.
  • Prefer signed artifacts and verifiable build provenance, such as Sigstore attestations or platform-specific package signatures.
  • Download the installer as a separate file so users can inspect it before execution.
  • Document the exact files, hooks, configuration changes, and permissions created by installation.
  • Avoid requiring administrative privileges unless a specific operation genuinely requires them.
  • Include the installer source in the reviewed project, or otherwise ensure that the reviewed version is cryptographically bound to the downloaded version.

A safer installation flow would resemble:

bash
curl -fL -o install.sh https://example.invalid/releases/vX.Y.Z/install.sh
echo '<EXPECTED_SHA256>  install.sh' | sha256sum -c -
less install.sh
bash install.sh
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (3)

Chaining Abuse

High
Category
Tool Misuse
Confidence
99% confidence
Finding

The shell pipeline into bash is the core dangerous behavior: it turns network-delivered content into immediate command execution. This pattern is especially risky in a skill because users may copy-paste it verbatim, and any compromise of the source or transit path can result in full arbitrary code execution.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Installation

bash
curl -fsSL https://raw.githubusercontent.com/weykon/agent-hand/master/install.sh | bash

Installs the agent-hand binary. Works on macOS (ARM + Intel) and Linux.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs users to execute a remotely fetched script directly with bash, which removes any opportunity to inspect the code before execution. If the GitHub content, repository, branch, or delivery path is compromised, arbitrary commands would run immediately on the user's machine with the user's privileges.

Content

No source excerpt is available for this finding.

External Script Fetching

Low
Category
Supply Chain
Confidence
94% confidence
Finding

Fetching and executing code from an external URL introduces a trust boundary to third-party content that can change over time. In this context, the risk is elevated because the external content is not merely downloaded but is part of an installation flow that leads directly to code execution.

Content

Scanner excerpt · SKILL.md (reported line 19)May include surrounding context.

Installation

bash
curl -fsSL https://raw.githubusercontent.com/weykon/agent-hand/master/install.sh | bash

Installs the agent-hand binary. Works on macOS (ARM + Intel) and Linux.

Static analysis

No suspicious patterns detected.