T03 · Remote Payload Retrieval and Execution
- Location
setup.sh:107- Finding
Unpinned Remote Components Are Downloaded and Executed
- Content
View full analysis
/dev/null || \ { print_error "Failed to clone pyenv. Please check network or install manually:" echo " git clone --depth 1 https://github.com/pyenv/pyenv.git $HOME/.pyenv" exit 2 } ``` ```bash eval "$(pyenv init --path 2>/dev/null)" || true eval "$(pyenv virtualenv-init - 2>/dev/null)" || true ``` ```bash output=$(clawhub install "$skill" 2>&1) ``` ```bash "$REQUIRED_PYTHON" -m venv .venv && \ source .venv/bin/activate && \ pip install --upgrade pip -q && \ pip install -r requirements.txt -q 2>&1 ``` ### Technical Analysis The installer retrieves pyenv from the mutable default branch without pinning a reviewed commit or verifying a signature or checksum. It also installs six ClawHub Skills without specifying immutable versions. Code generated by the downloaded pyenv installation is subsequently evaluated by the shell. The downloaded Skills' dependency manifests are then passed to `pip install`. Python package installation may execute build backends and setup hooks, so a compromised Skill manifest or dependency can execute arbitrary code during setup. The use of the official pyenv GitHub repository reduces the likelihood of malicious content compared with an unknown paste service, but it does not eliminate the risks associated with mutable remote content, upstream compromise, account takeover, DNS/TLS trust failures, or an unsafe dependency update. The six downloaded ClawHub Skills were not included in the audited artifact, so their effective payloads could not be reviewed. This behavior is relevant to the declared one-click installer functionality, but automatic execution of unpinned remote content is broader than the mini ...[truncated 1275 chars]- Remediation
View remediation
