T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Mutable Remote Installer Is Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This WhatsApp auto-reply skill is purpose-aligned, but it needs review because it installs unverified remote code, runs persistently, and lets private messages drive a broadly capable agent.
Install only after reviewing and verifying the upstream installer and binary. Use a dedicated least-privileged OpenClaw agent for WhatsApp replies, restrict replies with an allowlist, avoid storing queues and logs in shared `/tmp`, tighten file permissions, and know how to stop and remove the user service before linking a real WhatsApp account.
SKILL.md:30Unverified Mutable Remote Installer Is Executed Directly
SKILL.md:104Unverified External Binary Is Installed as an Automatically Restarting Service
scripts/wa-notify-worker.sh:58Untrusted WhatsApp Content Is Passed to a Tool-Capable Agent Without an Enforced Trust Boundary
scripts/wa-notify.sh:14Sensitive Message Queue Uses Predictable Temporary Paths Without Secure Permission or Symlink Controls
Piping curl output directly into bash creates an immediate remote-code-execution chain with no inspection or integrity verification step. In the context of a skill that later installs binaries, scripts, background workers, and persistent services, this is especially dangerous because a compromised installer could establish durable access and process sensitive WhatsApp data.
curl -fsSL https://raw.githubusercontent.com/0xs4m1337/openclaw-whatsapp/main/install.sh | bash
Verify installation:
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
[ -z "$jid" ] && return 0
local history
history=$(curl -s "http://localhost:8555/chats/${jid}/messages?limit=10" | python3 - <<'PY'
import json,sys
try:
data=json.loads(sys.stdin.read())
The skill documents extensive shell-based capabilities, including installation, service creation, script copying, and background worker execution, but does not declare any explicit tool scope or permissions boundary. That omission reduces transparency and reviewability, making it easier for users or agent frameworks to invoke powerful local actions without clear consent expectations.
The skill enables automatic AI replies to WhatsApp direct messages and processes chat history, contacts, and session data, but the introductory description does not prominently warn users about these privacy-sensitive behaviors. Users may enable it without understanding that inbound messages can be automatically processed by an AI agent and that message history and contacts may be stored or searched.
This instruction tells the user to copy an executable script into /usr/local/bin using sudo, which requires elevated privileges and places a locally sourced script into a trusted execution path. If the skill directory or script contents are tampered with, this becomes a privilege-assisted persistence or execution vector.
SKILL_DIR="$(dirname "$(realpath "$0")")" # or use absolute path to skill
sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh
This line performs another privileged copy of an executable worker script into /usr/local/bin. Because the script is later used for background processing of messages, a compromised or modified script would gain trusted placement and be harder for users to notice.
sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh
Using sudo chmod to make the copied scripts executable completes a privileged installation flow for code sourced from the skill directory. On its own chmod is not dangerous, but in this context it operationalizes code that may not have been independently verified.
sudo cp "$SKILL_DIR/scripts/wa-notify.sh" /usr/local/bin/wa-notify.sh sudo cp "$SKILL_DIR/scripts/wa-notify-worker.sh" /usr/local/bin/wa-notify-worker.sh sudo chmod +x /usr/local/bin/wa-notify.sh /usr/local/bin/wa-notify-worker.sh
Or if running as agent, use the skill directory path directly:
The use of nohup to launch a worker script creates background execution detached from the initiating session, which is a persistence-adjacent behavior. In this skill, that worker handles queued message processing, so compromise or misuse could allow hidden long-running processing of private communications.
Also update the worker script path in /usr/local/bin/wa-notify.sh:
# Find this line near the bottom:
nohup /home/oussama/dev/openclaw-whatsapp/scripts/wa-notify-worker.sh
# Change to:
nohup /usr/local/bin/wa-notify-worker.sh
This line shows the replacement nohup command used to keep the worker running independently after invocation. That behavior is legitimate for queue processing, but it still creates a long-lived background component that may continue operating on messages without obvious user visibility.
nohup /home/oussama/dev/openclaw-whatsapp/scripts/wa-notify-worker.sh
nohup /usr/local/bin/wa-notify-worker.sh
### Step 5: Create config file
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
nohup /usr/local/bin/wa-notify-worker.sh
### Step 5: Create config file
```bash
mkdir -p ~/.openclaw-whatsapp
The instructions create a user-level systemd service file that causes the WhatsApp bridge to run continuously in the background. In context this is functional persistence rather than overt malware behavior, but it still materially increases risk by maintaining long-lived access to chats, contacts, and session tokens.
EOF
### Step 6: Create systemd service (recommended)
```bash
mkdir -p ~/.config/systemd/user
Enabling a user systemd service creates persistence so the bridge restarts automatically and continues processing WhatsApp messages in the background. Persistence is expected for a messaging bridge, but it also increases the impact of compromise because the service can survive reboots and continue accessing message/session data.
EOF
systemctl --user daemon-reload systemctl --user enable openclaw-whatsapp.service systemctl --user start openclaw-whatsapp.service
This markdown file describes endpoints that retrieve chat histories, synced contacts, and webhook payloads containing names, phone numbers, and message content, but it provides no user-facing warning about the privacy implications of accessing or transmitting that data. Under the markdown-file criteria, documentation should warn when behavior can affect user data or privacy.
The worker forwards WhatsApp message content, contact identifiers, and recent chat history into an external agent process, which expands the trust boundary and can expose sensitive user data to an LLM or downstream tooling without any enforcement of consent, minimization, or clear disclosure at this layer. In a messaging bridge with auto-replies, this is security-relevant because private conversations are being programmatically processed and could be logged, retained, or mishandled by the agent.
This code creates a data directory and persistent queue/deduplication files, then stores chat message content and message IDs there. The file contains no confirmation, print/log disclosure, or comment warning users that message data will be retained on disk.
The script launches a background worker with nohup, causing additional processing outside the current shell invocation. Although there is an internal comment, there is no user-facing disclosure, prompt, or visible logging to inform users that a detached process will be started.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
# Worker path: configurable via OC_WA_WORKER_PATH, or same directory as this script
WORKER_PATH="${OC_WA_WORKER_PATH:-$(dirname "$(realpath "$0")")/wa-notify-worker.sh}"
[ ! -x "$WORKER_PATH" ] && WORKER_PATH="/usr/local/bin/wa-notify-worker.sh"
nohup "$WORKER_PATH" >/dev/null 2>&1 &
exit 0
The skill instructs users to fetch and execute an installation script directly from a remote GitHub URL. This bypasses normal package trust controls and exposes users to repository compromise, account takeover, DNS/TLS interception edge cases, or silent upstream script changes.
curl -fsSL https://raw.githubusercontent.com/0xs4m1337/openclaw-whatsapp/main/install.sh | bash
Verify installation:
The API reference lists a POST /logout endpoint that unlinks the WhatsApp device, which is an integrity-affecting action, but the markdown gives no caution about its effect or reversibility. For markdown files, destructive or system-affecting behaviors should be accompanied by a clear warning.
The script reads OC_WA_SYSTEM_PROMPT from the environment and embeds it into queued event data, but there is no warning or comment explaining that environment-provided prompt content will be captured and forwarded for later processing. This is a form of sensitive configuration handling that lacks explicit disclosure in the file.
No suspicious patterns detected.