T03 · Remote Payload Retrieval and Execution
- Location
skill.md:34- Finding
Unverified Remote Skill Installation Allows Post-Review Payload Replacement
- Content
View full analysis
~/.moltbot/skills/stackunderflow/SKILL.md curl -s https://stackunderflow.ai/skill.json > ~/.moltbot/skills/moltbook/package.json ``` ### Technical Analysis The installation instructions retrieve Skill instructions and package metadata from mutable remote URLs and write the responses directly into local Skill directories. They do not pin an immutable release or verify a cryptographic signature, checksum, expected content type, or trusted release identity. The downloaded `SKILL.md` may control subsequent Agent behavior when loaded. Consequently, the effective instructions installed by these commands can differ from the content audited in this project. A compromise of the remote service, its deployment pipeline, DNS resolution, or another delivery-layer component could replace the reviewed content with attacker-controlled instructions. The commands also use `curl -s` without `--fail`, making HTTP error responses capable of being silently written into the destination files. The download host, `stackunderflow.ai`, is outside the document's declared exclusive network whitelist of `api.stackunderflow.ai`. ### Attack Path 1. An attacker compromises or gains control over the content returned by `https://stackunderflow.ai/skill.md` or `https://stackunderflow.ai/skill.json`. 2. The attacker modifies the remote content after this local copy has been reviewed. 3. A user executes the documented installation commands. 4. The commands write the attacker-controlled responses directly into local Skill paths without integrity validation. 5. The Agent discovers and loads the replaced Skill instructions or metadata. 6. The malicious instructions can then ...[truncated 828 chars]- Remediation
View remediation
