T03 · Remote Payload Retrieval and Execution
- Location
references/marketplace.md:29- Finding
Remote Marketplace Strategy Code Is Executed Without an Enforced Security Boundary
- Content
View full analysis
Vulnerability Details
File Location:
references/marketplace.md:29-39, 90-93, 135-142
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighRelevant snippets:
markdown Fetch strategy code (requires purchase): GET /openclaw/marketplace/strategies/{id}/code Response: `{"code": "..."}` — save to `.py` and run with `python3`. **Flow when user wants to run a purchased strategy:** 1. `GET /openclaw/marketplace/my/purchases` — show the list 2. User picks one → `GET /openclaw/marketplace/strategies/{id}/code` 3. Save to `/tmp/<filename>.py` 4. **Check for multi-strategy bundle** — scan for `# ===== STRATEGY \d+:` markers: - If found: split into separate files and deploy each - If not found: `python3 filename.py`markdown **Deploying** — when downloaded code contains `# ===== STRATEGY N:` markers: 1. Split at each marker into N separate strings 2. Save each to `/tmp/<name_slug>.py` 3. Security scan each file separately; skip any that exit 2 (critical) 4. Move approved files to `strategies/<name_slug>.py` and run each with `python3`markdown View strategies shared with you: GET /openclaw/marketplace/my/shared-with-me Download code (works for owned, purchased, or shared strategies): GET /openclaw/marketplace/strategies/{id}/code` Response: `{"code": "..."}` — save to `.py` and run with `python3`.Technical Analysis
The Skill instructs the Agent to retrieve Python source from a remote marketplace and execute it with the local Python interpreter. The effective payload is controlled by the marketplace strategy author and can change independently of the reviewed Skill package.
The ordinary purchased/shared strategy path executes a single-file response directly. A security scan is mentioned only for files recognized as multi-strategy bundles, and the document does not identify or implement a scanner, define the checks performed, or ...[truncated 2222 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all instructions that directly execute marketplace-provided source with the host Python interpreter.
- Treat purchased, shared, private, bundled, and single-file strategies uniformly as untrusted code.
- Require a pinned content digest or signed artifact and verify it before review and execution. Display the strategy identity, publisher, version, and digest to the user.
- Implement a real, fail-closed review gate. If scanning fails, is unavailable, or returns an unknown result, execution must stop.
- Require explicit user approval after presenting the reviewed source, provenance, requested permissions, and scan result.
- Execute approved strategies in an isolated container or equivalent sandbox with:
- No inherited Blave or exchange credentials.
- A read-only root filesystem and a dedicated writable working directory.
- No host filesystem mounts except narrowly selected inputs.
- Network access denied by default and allowlisted only when required.
- A non-privileged user, dropped capabilities, resource limits, and execution timeouts.
- Do not move remotely supplied files into trusted
strategies/paths until verification succeeds. - Use server-side immutable versions so code cannot change after purchase or approval without generating a new version and requiring renewed review.
- Avoid predictable temporary filenames and securely create temporary files, while recognizing that safe temporary-file handling alone does not mitigate arbitrary code execution.
