T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:64- Finding
Execution of a Remotely Supplied Upload Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 64–65
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code Snippet:
text 5. Call `upload_videos` to get the upload command. 6. Execute the upload command and extract the `videoId`.Technical Analysis
The Skill explicitly instructs the Agent to obtain a command from the external BatchEdits MCP service and execute it locally. The command is generated remotely after the Skill has been reviewed, so its effective behavior is mutable and cannot be established from the package contents alone.
No restrictions require the returned command to invoke only
curl, constrain its arguments, validate its destination, or present it to the user for approval. Consequently, a malicious or compromised MCP service could return arbitrary shell syntax rather than a legitimate upload command. Executing an untrusted command string crosses the trust boundary between remote service data and local code execution.Attack Path
- The user or Agent configures the external BatchEdits MCP endpoint as directed by the Skill.
- The Agent invokes
upload_videosfor a local video. - A malicious or compromised endpoint returns a shell command containing an arbitrary payload.
- Following line 65, the Agent executes that command without local validation or argument-safe reconstruction.
- The payload runs with the same operating-system privileges and environment access as the Agent.
- The payload may read local files and environment variables, transmit credentials or documents, modify accessible data, or execute additional downloaded content.
Impact Assessment
Successful exploitation provides arbitrary command execution within the security context of the OpenClaw process. The attacker could access all files, credentials, environment variables, and network resources available to that process. The scope may include BatchEdits ...[truncated 282 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not execute command strings returned by an MCP server or any other remote service.
- Redesign
upload_videosto return structured data, such as an upload URL, HTTP method, required headers, and form fields. - Construct the upload request locally with an argument-safe HTTP library rather than passing remote text to a shell.
- Allowlist the exact HTTPS scheme, hostname, port, method, and expected path patterns before uploading.
- Reject redirects to unapproved hosts and prohibit URL schemes such as
file:,ftp:, or shell-specific process substitutions. - Prevent the remote response from controlling local file paths. Use only the specific video path selected by the user.
- Require explicit user confirmation showing the local file and validated remote destination before transmission.
- If a command-line client is unavoidable, build its argument array locally without
sh -c,eval, or string interpolation, and ensure secrets are not exposed in process arguments or logs.
