T03 · Remote Payload Retrieval and Execution
- Location
scripts/setup.sh:101- Finding
Remote .NET Installer Downloaded and Executed Without Integrity Verification
- Content
View full analysis
> "$HOME/.bashrc" ``` ### Technical Analysis The setup process downloads a mutable shell script from an external URL and executes it immediately without checking a cryptographic checksum or digital signature. Although the URL uses HTTPS and belongs to Microsoft's official domain, transport encryption alone does not establish that the retrieved file is the exact payload reviewed by the project author. The effective installer can change after the Skill package has been audited. A compromise of the upstream distribution infrastructure, DNS or certificate trust chain, an enterprise TLS-inspection proxy, or the remote artifact itself could cause attacker-controlled shell code to be delivered and executed. The fixed path `/tmp/dotnet-install.sh` also creates a local race and symlink risk in shared environments. Another local user could potentially prepare or replace that path while setup is running. The unconditional overwrite reduces but does not fully eliminate race conditions between download, permission modification, and execution. ### Attack Path 1. A user follows the Skill instruction to run `bash scripts/setup.sh`. 2. The sc ...[truncated 1553 chars]- Remediation
View remediation
