T03 · Remote Payload Retrieval and Execution
- Location
references/ptengine-cli.md:5- Finding
Unverified Remote Installer Is Piped Directly to a Shell
- Content
View full analysis
Vulnerability Details
File Location:
references/ptengine-cli.md, lines 5–12
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash ## Installation ```bash # Via official install script (recommended) curl -sSL https://raw.githubusercontent.com/Kocoro-lab/ptengine-cli/v0.1.0/scripts/install.sh | sh # Or use the project's wrapper sh install.shtext ### Technical Analysis The documentation recommends downloading a shell script from a third-party GitHub namespace and piping the response directly into `sh`. The command references the mutable `v0.1.0` tag and performs no checksum or cryptographic signature verification before execution. Consequently, the code ultimately executed is not fixed by the audited Skill package. It may change if the upstream repository owner moves the tag, the GitHub account or repository is compromised, or an upstream maintainer publishes malicious content. Piping the response directly to a shell also prevents meaningful inspection before execution. This unsafe path bypasses the protections present in the local `install.sh` wrapper, which pins an immutable commit and validates the downloaded installer against a SHA-256 checksum. Calling the verified wrapper is sufficient for the declared functionality; therefore, the unverified pipe-to-shell alternative exceeds the minimum risk necessary to install the CLI. ### Attack Path 1. An attacker gains control of the upstream repository, maintainer account, or referenced mutable tag. 2. The attacker replaces the remote installer with a script containing arbitrary shell commands. 3. A user or Agent follows the documentation’s recommended installation command. 4. `curl` retrieves the attacker-controlled response. 5. The response is immediately passed to `sh` without checksum or signature validation. 6. The malicious commands execute with the privileges of the account running the Skill. ### Impact Assessment Successful expl ...[truncated 538 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the direct
curl | shcommand from the documentation. - Direct users exclusively to the hardened local wrapper:
bash sh install.sh - Preserve the wrapper’s immutable commit pin and SHA-256 verification.
- Prefer a cryptographic signature tied to a documented maintainer key when upstream support is available.
- Vendor the reviewed installer or binary into a controlled release process where practical.
- Review the complete upstream installer and any binaries it subsequently downloads; verifying only the first-stage script does not automatically establish the integrity of later-stage artifacts.
- Run installation without elevated privileges and install only within a user-controlled directory.
- Document the expected files, network destinations, and credential locations so users can verify installation behavior.
- Remove the direct
