T03 · Remote Payload Retrieval and Execution
- Location
references/01-FOUNDATIONS.md:98- Finding
Unverified OpenClaw and NodeSource Scripts Executed Directly by a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a searchable OpenClaw course reference, but it includes multiple copy-paste setup examples that can run unverified or overprivileged commands on a user's machine or server.
Review this skill before installing or using its output as commands. It is not showing hidden exfiltration or automatic destructive behavior, but users should avoid blindly running the remote installer, privileged Docker, systemd, and autonomous coding-agent examples; verify installers, avoid Docker socket exposure where possible, keep secrets out of logs, and harden any persistent service before deployment.
references/01-FOUNDATIONS.md:98Unverified OpenClaw and NodeSource Scripts Executed Directly by a Shell
references/04-CONTEXT-AND-COSTS.md:37Unverified Ollama Installer Executed Directly by a Shell
references/05-VPS-EMPLOYEE.md:142Unverified NodeSource Setup Script Executed with Administrative Privileges
references/03-LOCAL-POWER.md:1163Command Injection Through Unescaped Agent, Filename, and Model-Generated Values
references/05-VPS-EMPLOYEE.md:237Gateway Password Disclosed to Terminal and Process Logs
references/05-VPS-EMPLOYEE.md:486Persistent OpenClaw Service Explicitly Disables Key Systemd Isolation Controls
references/06-SECURITY.md:568Privileged Audit Reports Written Through Predictable Paths in Shared Temporary Storage
Referenced artifact was not completely inspected
- `SKILL.md`, `manifest`, `clawhub`
Referenced artifact was not completely inspected
- `references`, `scripts`, `index.js`
curl -fsSL https://openclaw.ai/install.sh | bash is a classic unsafe install pattern that executes network-delivered code immediately. Any compromise of the distribution path or installer content leads directly to arbitrary command execution on the user's machine.
macOS/Linux:
curl -fsSL https://openclaw.ai/install.sh | bash
Windows (PowerShell):
Piping an externally retrieved installer script directly to bash creates a one-step arbitrary code execution path with no opportunity for integrity verification or review. In documentation for an AI agent platform, this is especially risky because users may copy-paste it unquestioningly during setup.
macOS/Linux:
curl -fsSL https://openclaw.ai/install.sh | bash
Windows (PowerShell):
Chaining a network fetch directly into sudo -E bash - combines two high-risk operations: unverified remote content and privileged execution. This magnifies the impact of any upstream compromise into full root-level code execution on the host.
# Install Node.js 22+ using NodeSource
curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -
sudo apt-get install -y nodejs
# Verify installation
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Additional WSL2 optimizations
echo '[interop]
appendWindowsPath=false' | sudo tee /etc/wsl.conf
# Restart WSL
wsl --shutdown
Documenting OPENCLAW_DOCKER_SOCKET=/var/run/docker.sock as part of a sandbox setup normalizes direct host Docker API exposure. Any code path able to access that socket can control the Docker daemon, start privileged containers, mount host filesystems, and effectively take over the host.
# Enable sandboxing for Docker deployments
export OPENCLAW_SANDBOX=1
export OPENCLAW_DOCKER_SOCKET=/var/run/docker.sock
# Run with sandbox capability
docker run -d \
--privileged disables most container isolation protections and grants extensive kernel/device capabilities. In combination with an AI agent platform that may execute tools or untrusted workflows, this materially increases the chance of host compromise through container escape or abuse of granted privileges.
docker run -d \
--name openclaw-gateway \
-p 18789:18789 \
--privileged \
-v /var/run/docker.sock:/var/run/docker.sock \
-v ~/.openclaw:/root/.openclaw \
openclaw/openclaw:latest
Mounting /var/run/docker.sock into the container gives processes inside the container direct access to the host Docker daemon. This effectively defeats container isolation because the container can create or control sibling containers with arbitrary host mounts and privileges.
--name openclaw-gateway
-p 18789:18789
--privileged
-v /var/run/docker.sock:/var/run/docker.sock
-v ~/.openclaw:/root/.openclaw
openclaw/openclaw:latest
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
Check API Key:
# Test API key
curl -H "x-api-key: $ANTHROPIC_API_KEY" \
https://api.anthropic.com/v1/models
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
npm update -g openclaw@latest
# Clear cache if needed
rm -rf ~/.openclaw/.cache
# Restart gateway
openclaw gateway restart
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
npm update -g openclaw@latest
# Clear cache if needed
rm -rf ~/.openclaw/.cache
# Restart gateway
openclaw gateway restart
The quick reference repeats the same unsafe curl | bash pattern, reinforcing risky behavior and increasing the chance users will execute it verbatim. Repetition in a summary section makes the issue more dangerous because quick-reference blocks are commonly copy-pasted without reading surrounding context.
# Installation
curl -fsSL https://openclaw.ai/install.sh | bash
npm install -g openclaw@latest
# Onboarding
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
## Vibe
Calm, organized, and dependable. The eye of the hurricane.
Speak with quiet confidence. Don't apologize for normal delays.
## Communication Style
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
2. [Voice Input with Whisper/FFmpeg](#voice-input-with-whisperffmpeg)
3. [Local Image Generation with ComfyUI](#local-image-generation-with-comfyui)
4. [Agentic Coding with Claude Code/Codex/OpenCode](#agentic-coding-with-claude-codecodexopcode)
5. [Self-Modifying Agents](#self-modifying-agents)
6. [Integration Patterns](#integration-patterns)
---
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
2. [Voice Input with Whisper/FFmpeg](#voice-input-with-whisperffmpeg)
3. [Local Image Generation with ComfyUI](#local-image-generation-with-comfyui)
4. [Agentic Coding with Claude Code/Codex/OpenCode](#agentic-coding-with-claude-codecodexopcode)
5. [Self-Modifying Agents](#self-modifying-agents)
6. [Integration Patterns](#integration-patterns)
---
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
# ~/.openclaw/.env
OPENAI_API_KEY=sk-...
The example recommends delegating work to an external model provider using claude --print --permission-mode bypassPermissions, combining third-party code generation with reduced safeguards. This can expose source code or prompts to an external provider and permit broad automated modifications without normal confirmation controls.
# Quick one-shot task (no PTY needed)
claude --print --permission-mode bypassPermissions "Refactor this function"
# Interactive session (PTY required)
claude
codex exec --full-auto delegates implementation to an external coding agent in autonomous mode, creating both data-sharing and uncontrolled-change risk. In a skill about powerful local tooling, this is especially dangerous because it can chain into shell execution and repository modification.
# Full auto mode
codex exec --full-auto "Add user authentication"
# With yolo mode (less confirmation)
codex exec --yolo "Fix the bug in utils.py"
codex exec --yolo further lowers confirmation barriers for an external coding agent, increasing the likelihood of unsafe edits, dependency additions, or command execution. The example lacks compensating controls such as sandboxing, diff review, or data-sharing warnings.
codex exec --full-auto "Add user authentication"
codex exec --yolo "Fix the bug in utils.py"
From OpenClaw:
Selecting a specific external model/provider via kilo run --model claude-sonnet-4 is not inherently malicious, but it does create undisclosed third-party processing and model-routing risk if used without consent boundaries. The concern is heightened because the surrounding guidance encourages broad coding delegation.
kilo run "Implement pagination"
kilo run --model claude-sonnet-4 "Complex refactoring"
### Agentic Coding Examples
The example constructs shell commands with interpolated variables in paths, such as /tmp/pr-${pr}-review, and executes them directly. Even if pr looks numeric in the sample, this pattern normalizes command construction without validation or escaping and can become command/path injection if adapted to less trusted inputs.
await postPRReview(pr, log);
// Cleanup
await exec({ command: git worktree remove /tmp/pr-${pr}-review });
}
Detected: suspicious.destructive_delete_command, suspicious.exposed_secret_literal