T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:165- Finding
Unpinned Remote Executable Downloaded and Run Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 165–174
Vulnerability Type: Mutable remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash archive_name="ai-photos_${goos}_${goarch}.tar.gz" archive_url="https://github.com/${AI_PHOTOS_REPO}/releases/latest/download/${archive_name}" tmp_dir="$(mktemp -d)" had_existing_binary=0 if [ -x "$AI_PHOTOS_BIN" ]; then had_existing_binary=1 fi if curl -fL "${archive_url}" -o "$tmp_dir/${archive_name}" \ && tar -xzf "$tmp_dir/${archive_name}" -C "$tmp_dir" \ && install -m 0755 "$tmp_dir/ai-photos" "$AI_PHOTOS_BIN"; thenTechnical Analysis
The bootstrap process downloads an executable archive through the mutable GitHub
releases/latestURL. It then extracts and installs the containedai-photosbinary with executable permissions without verifying a cryptographic checksum or signature.Because the URL does not pin a reviewed version or immutable asset digest, the effective code executed by the Skill can change after the Skill itself has been audited. HTTPS protects transport integrity but does not protect against compromise of the upstream repository, maintainer account, release workflow, or release artifact.
The installed executable is subsequently used for operations including photo discovery, image preparation, backend setup, record import, search, local web serving, and recurring synchronization. Consequently, a substituted executable would run in a context with access to the user's photo sources and other resources available to the Agent's operating-system account.
Attack Path
- An attacker compromises the upstream repository, maintainer credentials, release workflow, or GitHub release assets.
- The attacker publishes or replaces the archive selected by the mutable
releases/latest/download/...URL. - At the beginning of an
ai-photostask, the mandated bootstrap process downloads the attacker-controlled archive. - The process extracts ...[truncated 1230 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specific reviewed release version rather than using
releases/latest. - Publish SHA-256 hashes through a separately protected release process and embed or securely obtain the expected platform-specific digest.
- Verify the archive before extraction, for example with
sha256sum -corshasum -a 256, and fail closed on any mismatch. - Prefer cryptographically signed artifacts and verify the signature against a pinned, trusted public key.
- Do not install or execute an artifact when integrity or authenticity verification fails.
- Download to a private temporary directory and validate that the archive contains only the expected file paths before extraction.
- Extract using protections against path traversal and reject symbolic links, absolute paths, unexpected entries, and duplicate executable entries.
- Verify the extracted file's type and expected metadata before atomically replacing the cached binary.
- Retain a previously verified binary only if its version and digest are recorded and revalidated before use.
- Document a controlled update procedure so new releases undergo review and digest updates before deployment.
- Pin the CLI to a specific reviewed release version rather than using
