T03 · Remote Payload Retrieval and Execution
- Location
INSTALL.md:5- Finding
Unverified Remote Installer Is Piped Directly into Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill mostly matches its stated Xianyu scraping purpose, but it uses unsafe installation, self-update, persistence, credential, and upload behavior that should be reviewed before use.
Review this skill carefully before installing. Avoid the curl | bash flow and sudo, disable or remove cron and self-update unless you can verify the code source, keep any Gitee token and Xianyu cookie narrowly scoped, use a private upload destination, and inspect exactly which screenshots and data files will be pushed.
INSTALL.md:5Unverified Remote Installer Is Piped Directly into Bash
update.sh:24Self-Updater Replaces Executable Skill Files with an Unverified Remote Archive
install.sh:109Installer Automatically Adds Persistent Recurring Cron Jobs
grabber.js:99User-Controlled Keywords Reach Shell Commands through Screenshot Filenames
uploader.sh:64Gitee Access Token Is Exposed in Git Process Arguments
install.sh:79Credential Configuration Is Created without the Documented Restrictive Permissions
visualize.py:107Generated HTML Reports Embed Unescaped Attacker-Controlled Values
install.sh:42Installer Uses Unpinned Dependencies and Bypasses Python Environment Protections
uploader.sh:34Uploader Broadly Collects Data and Screenshots and Force-Pushes Them despite Conflicting Privacy Claims
The install instructions explicitly tell users to pipe a remote script from GitHub directly into bash, which executes unreviewed code immediately with no integrity check or review step. In the context of a skill that installs dependencies, modifies configuration, and sets scheduled tasks, this materially increases the risk of arbitrary code execution and full host compromise if the remote content is tampered with or the repository is malicious.
The | bash chain removes any opportunity for the user or platform to inspect the downloaded script before execution, turning a remote fetch into immediate arbitrary command execution. In this skill's context—where installation can add cron jobs, install packages, and modify local files—this pattern is especially dangerous because it can establish persistence and system-level changes in one step.
复制以下命令,发送给 OpenClaw 执行:
curl -sL https://raw.githubusercontent.com/your-username/xianyu-data-grabber/main/install.sh | bash
或者本地安装:
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber
# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber
# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber
# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
# 删除技能目录
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber
# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/workspace/skills/xianyu-data-grabber
# 删除配置文件
rm ~/.openclaw/workspace/.xianyu-grabber-config.json
# 删除定时任务
crontab -l | grep -v xianyu | crontab -
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
crontab -l | grep -v xianyu | crontab -
rm -rf ~/.openclaw/workspace/legion/data/xianyu-* rm -rf ~/.openclaw/workspace/legion/screenshots/xianyu-*
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
rm -rf ~/.openclaw/workspace/legion/data/xianyu-* rm -rf ~/.openclaw/workspace/legion/screenshots/xianyu-*
---
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
The documentation emphasizes scraping and OCR, but it also describes reading a local config containing credentials and pushing content to a remote Gitee repository. Sensitive external write capability combined with local credential access is a materially risky behavior that should be explicitly declared and tightly scoped.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
echo " recommend 生成智能推荐(选品/定价/利润)"
echo " cron 配置定时任务"
echo " check-update 检查新版本"
echo " self-update 自动更新到最新版本"
echo " clean 清理临时文件"
echo " status 显示当前状态"
echo " help 显示帮助"
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
echo " recommend 生成智能推荐(选品/定价/利润)"
echo " cron 配置定时任务"
echo " check-update 检查新版本"
echo " self-update 自动更新到最新版本"
echo " clean 清理临时文件"
echo " status 显示当前状态"
echo " help 显示帮助"
The do_self_update() function is a true self-modification primitive because it launches an update script that can alter the local installation. In the context of a scraping skill that already interfaces with external content and uploads data, adding silent self-modification materially increases supply-chain and arbitrary code execution risk.
}
# 自动更新
do_self_update() {
echo "🔄 自动更新..."
bash "$SCRIPT_DIR/update.sh"
}
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
do_check_update
;;
self-update)
do_self_update
;;
clean)
do_clean
The updater deletes the current skill directory contents and copies in newly downloaded files without any confirmation, integrity validation, or safety interlock. If the download is malicious, corrupt, or incomplete, this can destroy the installed skill and replace it with attacker-controlled code or leave the environment broken.
The command rm -rf "$SCRIPT_DIR"/* performs destructive deletion based on a computed path and executes before any robust validation or atomic replacement. Even with quoting, logic errors, unexpected path resolution, partial updates, or manipulated runtime context can cause irreversible data loss or enable destructive behavior beyond the intended update flow.
# 覆盖安装
echo "🔄 安装新版本..."
rm -rf "$SCRIPT_DIR"/*
cp -r "$UPDATE_DIR"/* "$SCRIPT_DIR/"
echo "✅ 安装完成"
echo ""
The script force-pushes collected files to a remote Gitee repository using an embedded token in the push URL, without an interactive warning or approval step. This is dangerous because it transmits local data off-host and can overwrite remote history, so misuse, misconfiguration, or adversarial modification of input paths could cause unintended disclosure and destructive repository changes.
Detected: suspicious.dangerous_exec, suspicious.destructive_delete_command