T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:20- Finding
Unverified Remote Installer Is Executed Directly by a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent setup purpose, but it asks users to run mutable remote installers, install a binary system-wide, and activate a remotely fetched skill without integrity verification.
Review this skill carefully before installing. Prefer pinned releases, verified checksums or signatures, user-local installation paths, and a reviewed pinned copy of openclaw-in-a-box. Treat the tapes database as sensitive because it can contain prompts and responses, and avoid placing ingest keys in shell history or shared environment logs.
SKILL.md:20Unverified Remote Installer Is Executed Directly by a Shell
SKILL.md:36Mutable Release Binary Is Extracted and Installed Without Integrity Verification
SKILL.md:78Mutable Remote Skill Instructions Are Downloaded and Subsequently Invoked
This is a classic external script fetching issue: code is retrieved from a remote URL and immediately executed locally. If the hosting service, DNS, CDN, or publishing account is compromised, the installer becomes an instant remote code execution vector against anyone following the skill.
command -v tapes && tapes --version || curl -fsSL https://download.tapes.dev/install | bash
If the curl install fails, try: brew install papercomputeco/tap/tapes
The explicit pipe into bash removes any review opportunity and chains untrusted network input straight into command execution. In a setup skill, users are especially likely to copy-paste such commands, which makes this pattern a high-probability arbitrary code execution hazard.
command -v tapes && tapes --version || curl -fsSL https://download.tapes.dev/install | bash
If the curl install fails, try: brew install papercomputeco/tap/tapes
The skill explicitly installs telemetry that records every AI request and response into local storage, creating a substantial data-capture surface for prompts, outputs, and potentially secrets or proprietary content. Even though the later description says clawtel only uploads aggregate token metrics, the local collection itself increases privacy and compliance risk if the host is shared or compromised.
The skill instructs users to fetch a network-delivered installer and pipe it directly to bash, which executes unauthenticated remote code immediately. This is dangerous because any compromise of the distribution endpoint, TLS-terminating infrastructure, or release pipeline would result in arbitrary code execution on the host during setup.
The skill tells users to export a sensitive ingest key directly in the shell without warning about shell history, process exposure, or secure secret storage. This can leak the key through terminal logs, history files, screenshots, shared shell sessions, or inherited environment variables.
The skill persists a remotely fetched SKILL.md into the local skills directory, creating a durable trust boundary crossing: future agent behavior may be influenced by unverified content retrieved from the network. In the context of agent skills, persistent installation is more dangerous because it can survive the setup session and affect later invocations or orchestration flows.
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
-o skills/openclaw-in-a-box/SKILL.md
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
-o skills/openclaw-in-a-box/SKILL.md
Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
-o skills/openclaw-in-a-box/SKILL.md
Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
-o skills/openclaw-in-a-box/SKILL.md
Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
mkdir -p skills/openclaw-in-a-box
curl -fsSL https://raw.githubusercontent.com/papercomputeco/openclaw-in-a-box/main/SKILL.md \
-o skills/openclaw-in-a-box/SKILL.md
Verify: head -5 skills/openclaw-in-a-box/SKILL.md should show name: openclaw-in-a-box.
No suspicious patterns detected.