T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:19- Finding
Unverified Remote Installer Executed Directly Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 19
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash curl -fsSL https://raw.githubusercontent.com/weykon/agent-hand/master/install.sh | bashTechnical Analysis
The installation command retrieves
install.shfrom the mutablemasterbranch of an external GitHub repository and pipes the response directly into Bash. The downloaded content is executed without being displayed, reviewed, pinned to an immutable commit or release, or validated with a cryptographic checksum or signature.Because the installer is not included in the audited project, its behavior cannot be verified from the available artifact. The effective payload can also change after this Skill has been reviewed. Compromise of the upstream repository, its maintainer account, or its delivery path could therefore turn the documented installation command into an arbitrary-code execution channel.
Direct execution is not necessary merely to provide installation instructions and exceeds the minimum-risk approach appropriate for the declared functionality.
Attack Path
- An attacker compromises the upstream repository or maintainer account, or otherwise gains the ability to modify
master/install.sh. - The attacker replaces or modifies the installer to include malicious shell commands.
- A user follows the installation command documented in
SKILL.md. curldownloads the current attacker-controlled script.- The shell immediately executes the response without integrity verification or user inspection.
- The payload performs arbitrary actions with the privileges of the user running the command.
Impact Assessment
Successful exploitation permits arbitrary command execution under the installing user's account. The payload could read or modify files accessible to that account, access developer credentials and agent configuration, install o ...[truncated 397 chars]
- An attacker compromises the upstream repository or maintainer account, or otherwise gains the ability to modify
- Remediation
View remediation
Remediation Suggestions
- Do not pipe network responses directly into a shell.
- Publish versioned release artifacts and reference an immutable release version or commit rather than the mutable
masterbranch. - Provide a cryptographic SHA-256 checksum through an independently protected channel and require users to verify it before execution.
- Prefer signed artifacts and verifiable build provenance, such as Sigstore attestations or platform-specific package signatures.
- Download the installer as a separate file so users can inspect it before execution.
- Document the exact files, hooks, configuration changes, and permissions created by installation.
- Avoid requiring administrative privileges unless a specific operation genuinely requires them.
- Include the installer source in the reviewed project, or otherwise ensure that the reviewed version is cryptographically bound to the downloaded version.
A safer installation flow would resemble:
bash curl -fL -o install.sh https://example.invalid/releases/vX.Y.Z/install.sh echo '<EXPECTED_SHA256> install.sh' | sha256sum -c - less install.sh bash install.sh
