T03 · Remote Payload Retrieval and Execution
- Location
scripts/setup.sh:99- Finding
Unverified Native Executable Downloaded over Plaintext HTTP
- Content
View full analysis
> "$HOME/.bashrc" export PATH="$HOME/.local/bin:$PATH" fi ``` The English text substituted in the failure branch above represents the original informational message; the security-relevant commands and URL are unchanged. ### Technical Analysis The setup script downloads a native executable through unauthenticated plaintext HTTP. It does not verify a cryptographic checksum, digital signature, certificate-protected transport, or trusted package metadata before granting execute permission. Although the configured domain is associated with the declared Clustal Omega dependency, HTTP provides neither payload confidentiality nor authenticity. A network-positioned attacker can replace the response with an arbitrary executable. A compromise of the remote HTTP endpoint or its delivery infrastructure would have the same effect. The downloaded file is installed as `$HOME/.local/bin/clustalo`. The workflow subsequently executes `clustalo`, making the downloaded content an effective remote payload whose contents can change after the Skill package has been audited. The installer also adds `$HOME/.local/bin` to `.bashrc` if the path is absent. This increases exposure because the downloaded program remains discoverable in later shell sessions. ### Attack Path 1. A user follows the first-use setup instruction and executes `scripts/setup.sh`. 2. `clustalo` is not already installed. 3. Installati ...[truncated 1168 chars]- Remediation
View remediation
