T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:17- Finding
Unverified Remote Installer Piped Directly into Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17
Vulnerability Type: Remote payload retrieval and execution
Risk Level: CriticalVulnerable Code:
bash curl -sSL https://raw.githubusercontent.com/yinguobing/suanpan/main/install.sh | bashTechnical Analysis
The recommended installation command retrieves
install.shfrom the mutablemainbranch of an external personal GitHub repository and immediately executes its contents with Bash.The command provides no immutable commit or release pinning, checksum verification, cryptographic signature validation, local inspection step, or confirmation before execution. Because the installer is not included in the audited project, its effective behavior cannot be statically reviewed and may change after this Skill has been approved.
This behavior creates a remote code-execution and supply-chain channel. Compromise of the repository owner account, upstream repository, or relevant delivery infrastructure could cause arbitrary attacker-controlled shell commands to run on systems following the installation instructions.
Direct execution of mutable remote code exceeds the minimum privileges necessary for the Skill's stated function of translating natural-language bookkeeping requests into local
suanpanCLI commands. The same installation goal can be achieved using a versioned, integrity-verified artifact or an inspectable source build.Attack Path
- An attacker compromises the upstream repository or its maintainer account, or otherwise gains control over the referenced
install.sh. - The attacker modifies the script on the mutable
mainbranch to include malicious shell commands. - A user or agent follows the Skill's recommended installation instruction.
curldownloads the attacker's current script without integrity verification.- The shell pipeline passes the downloaded bytes directly to Bash.
- Bash executes the malicious commands w ...[truncated 777 chars]
- An attacker compromises the upstream repository or its maintainer account, or otherwise gains control over the referenced
- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | bashinstallation command. - Publish versioned release artifacts through a controlled release process.
- Pin downloads to an immutable release version or commit rather than the mutable
mainbranch. - Publish SHA-256 checksums and preferably cryptographic signatures, and require users to verify them before execution.
- Separate retrieval from execution so the installer can be inspected:
bash curl -fL -o install.sh "https://example.invalid/releases/vX.Y.Z/install.sh" echo "<trusted-sha256> install.sh" | sha256sum --check - less install.sh bash install.sh - Prefer package-manager installation or reproducible source builds from a pinned tag.
- Avoid requiring administrative privileges unless installation into a protected system directory is explicitly requested. Offer a user-local installation path by default.
- Include the installer in the review scope or document all filesystem, network, and privilege-sensitive operations it performs.
- Remove the direct
