T03 · Remote Payload Retrieval and Execution
- Location
resources/install.md:36- Finding
Unpinned Remote Plugin and Dependency Retrieval Can Execute Mutable External Code
- Content
View full analysis
Vulnerability Details
File Location:
resources/install.md, lines 36-43
Vulnerability Type: Mutable remote code retrieval and unsafe dependency installation
Risk Level: HighVulnerable Snippet
bash # Existing installation cd ~/.openclaw/extensions/acp git pull # New installation sources git clone https://github.com/coderXjeff/openclaw-acp-channel.git ~/.openclaw/extensions/acp # Fallback source git clone https://gitee.com/yi-kejing/openclaw-acp-channel.git ~/.openclaw/extensions/acp # Dependency installation cd ~/.openclaw/extensions/acp npm installTechnical Analysis
The installation workflow retrieves the current contents of a mutable remote branch using
git pullorgit clone. It does not pin an audited commit, verify a signed release, or validate a checksum. Consequently, the effective plugin payload can change after this Skill has been reviewed.The subsequent
npm installoperation may execute package lifecycle scripts, includingpreinstall,install, andpostinstall. A malicious upstream commit or compromised dependency can therefore execute arbitrary code with the permissions of the OpenClaw user.The fallback repository is hosted under a different account and no cryptographic equivalence or trust relationship with the primary repository is established.
Attack Path
- An attacker compromises the primary repository, fallback mirror, maintainer account, or an unpinned npm dependency.
- The attacker adds malicious plugin code or a dependency lifecycle script.
- A user follows the installation or update workflow.
git pullorgit cloneretrieves the attacker-controlled revision.npm installexecutes the malicious lifecycle script, or OpenClaw loads the malicious plugin after restart.- The payload executes under the OpenClaw user's local privileges.
Impact Assessment
Successful exploitation can provide arbitrary code execution ...[truncated 238 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a specific audited commit hash or signed release tag.
- Verify a published SHA-256 checksum or cryptographic release signature before installation.
- Commit and enforce a dependency lockfile, and use
npm ciinstead ofnpm install. - Initially install dependencies with
npm ci --ignore-scripts; explicitly review and allow only required lifecycle scripts. - Remove the fallback mirror or independently verify that its selected commit exactly matches the trusted upstream commit.
- Run plugin installation and build operations in a sandbox with restricted filesystem and network access.
- Do not automatically restart or load the plugin until integrity verification succeeds.
