T03 · Remote Payload Retrieval and Execution
- Location
references/install.md:24- Finding
Unverified Remote Installer Scripts Are Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:277-279references/install.md:24-35references/install.md:125-127references/gateway_ops.md:206-208
Vulnerability Type: Remote payload retrieval and immediate shell execution
Risk Level: CriticalVulnerable Code
SKILL.md:277-279:bash # Install (recommended) curl -fsSL https://openclaw.ai/install.sh | bashreferences/install.md:24-35:bash # macOS / Linux / WSL2 curl -fsSL https://openclaw.ai/install.sh | bash # Windows (PowerShell) iwr -useb https://openclaw.ai/install.ps1 | iexbash curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboardreferences/install.md:125-127:bash ### Re-run Installer (Recommended) curl -fsSL https://openclaw.ai/install.sh | bashreferences/gateway_ops.md:206-208:bash # Installer script (macOS / Linux) curl -fsSL https://openclaw.ai/install.sh | bashTechnical Analysis
These commands retrieve mutable content from an external server and immediately pass it to Bash or PowerShell for execution. There is no intervening review, version pinning, cryptographic signature verification, or pinned checksum validation.
TLS protects the network connection in transit but does not guarantee that the server will return the same installer that was reviewed. A compromise of the distribution server, publishing account, domain, DNS infrastructure, or certificate issuance process could cause arbitrary replacement content to be executed. The effective payload can therefore change after this Skill has passed review.
The installer is also documented as capable of installing prerequisites and setting up a long-running gateway daemon. Consequently, a malicious replacement could modify user files, access credentials available to the invoking process, install persistence, or alter system configuration. If the command is run from an ele ...[truncated 1629 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all
curl | bash,curl | sh, andInvoke-WebRequest | Invoke-Expressionrecommendations. - Publish versioned, immutable installer artifacts rather than relying on a mutable unversioned URL.
- Require users to download the installer without executing it:
bash curl -fL --proto '=https' --tlsv1.2 \ -o openclaw-install.sh \ https://openclaw.ai/releases/VERSION/install.sh - Publish a signed checksum manifest through an independently protected release channel.
- Verify both the publisher signature and a pinned SHA-256 digest before execution:
bash printf '%s %s\n' 'PINNED_SHA256' 'openclaw-install.sh' | sha256sum -c - - Allow and encourage inspection of the downloaded script before running it:
bash less openclaw-install.sh bash openclaw-install.sh - Prefer a pinned package release such as
openclaw@<verified-version>instead ofopenclaw@latest. - For source installation, pin a full commit hash, verify its signed release or tag, and review installation hooks before running package-manager commands.
- Explicitly advise users not to execute the installer as root unless a documented operation strictly requires elevation.
- Apply the corrected procedure consistently in
SKILL.md,references/install.md, andreferences/gateway_ops.mdso that no unsafe fallback remains.
- Remove all
