T03 · Remote Payload Retrieval and Execution
- Location
README.md:39- Finding
Mandatory Retrieval and Execution of an Unpinned Remote Repository
- Content
View full analysis
Vulnerability Details
File Location:
README.md:39-47;SKILL.md:16-23;SKILL.md:76-82;SKILL.md:146;SKILL.md:155-171
Vulnerability Type: Remote payload retrieval and supply-chain execution
Risk Level: MediumVulnerable Code and Instructions
README.md:39-47:bash Install FinResearchClaw locally first: ```bash git clone https://github.com/ChipmunkRPA/FinResearchClaw.git ~/.openclaw/workspace/AutoResearchClaw cd ~/.openclaw/workspace/AutoResearchClaw python3 -m venv .venv source .venv/bin/activate pip install -e .text `SKILL.md:16-23`: ```text Before using this skill for substantive completion, install and make available the local FinResearchClaw repo: 1. Clone or install `https://github.com/ChipmunkRPA/FinResearchClaw` 2. Ensure the local repo is available at `~/.openclaw/workspace/AutoResearchClaw` unless a different local path is intentionally configured 3. Ensure Python is available and create a task-local virtual environment when needed 4. Install memo-generation dependencies such as `python-docx` when DOCX output is required If FinResearchClaw is not installed locally and runnable, do not treat the full research workflow as ready. Fix that prerequisite first.SKILL.md:76-82:text - Invoke FinResearchClaw for every task handled by this skill, regardless of output format. - Execution for memo, email, and q-and-a outputs should all wrap the FinResearchClaw repo/workflow even if the accounting issue is straightforward. - The FinResearchClaw-backed run must occur before any user-facing technical conclusion is given. Do not short-circuit from clarified facts directly to an accounting answer. - The skill may create a task-local virtual environment for the run if needed. - Do not skip or bypass the FinResearchClaw path. If the repo is unavailable, dependencies are missing, or the workflow fails to run, stop and troubleshoot the FinResearchClaw envir ...[truncated 4051 chars]- Remediation
View remediation
Remediation Suggestions
- Pin FinResearchClaw to a specific, reviewed commit hash or cryptographically signed immutable release rather than cloning the mutable default branch.
- Publish and verify a cryptographic checksum or signature before installation or execution.
- Replace editable installation with a reproducible installation from a reviewed artifact.
- Lock all transitive Python dependencies to exact versions and hashes, and install them with hash verification enabled.
- Review the pinned repository and its build configuration before approving it as an execution dependency.
- Run external research tooling in a sandbox or container with a restricted filesystem, minimal environment variables, no unnecessary credentials, and network access limited to required destinations.
- Avoid making remote code execution mandatory. Require explicit user consent before fetching or executing external code, and provide a safe local-only fallback.
- Store the approved dependency in a versioned, read-only location and verify its integrity before each run.
- Document a controlled update process requiring security review whenever the pinned revision or dependency lock file changes.
