T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:45- Finding
Unverified Tailscale Installer Is Downloaded and Executed Directly
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real cloud deployment guide, but it asks users to run mutable remote installers and a persistent service with sensitive credentials and weak SSH setup.
Review each command before running it, use a dedicated disposable VM and least-privileged cloud project, pin and verify installer and npm package versions, restrict SSH source ranges or use a safer SSH path, and plan how to rotate credentials and remove the daemon.
SKILL.md:45Unverified Tailscale Installer Is Downloaded and Executed Directly
SKILL.md:56Unverified NVM Installer Is Downloaded and Executed Directly
SKILL.md:58Unpinned Latest OpenClaw Package Executes an Unreviewed Dependency Release
SKILL.md:41SSH Host Identity Verification Is Disabled During Initial Provisioning
SKILL.md:67Unverified OpenClaw Code Is Installed as a Persistent User Daemon
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
--machine-type=e2-medium \
--image-family=debian-12 --image-project=debian-cloud \
--boot-disk-size=10GB \
--metadata=ssh-keys="${OPENCLAW_USERNAME}:$(cat ~/.ssh/id_ed25519.pub)"
IP=$(gcloud compute instances describe "$VM" \
--project="$OPENCLAW_PROJECT_ID" --zone="$ZONE" \
The skill downloads and executes a remote installer script from tailscale.com via a shell pipe without integrity verification. If the remote content, DNS, TLS trust chain, or network path is compromised, arbitrary code executes on the VM with root-level effects due to the installation context.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Piping curl output directly to sh executes untrusted remote content immediately and removes any opportunity for review or integrity validation. In a provisioning script this can lead to full host compromise through arbitrary command execution.
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
# Manual: authorize Tailscale
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Continue setup
ssh "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo ufw allow 22/tcp && sudo ufw allow in on tailscale0 && echo y | sudo ufw enable
echo 'nameserver 8.8.8.8' | sudo tee -a /etc/resolv.conf
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
source ~/.nvm/nvm.sh && nvm install 22
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
# Continue setup
ssh "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo ufw allow 22/tcp && sudo ufw allow in on tailscale0 && echo y | sudo ufw enable
echo 'nameserver 8.8.8.8' | sudo tee -a /etc/resolv.conf
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
source ~/.nvm/nvm.sh && nvm install 22
Piping remote content directly to bash is unsafe because it executes whatever the network returns at that moment. This creates an avoidable arbitrary-code-execution path during setup.
set -euo pipefail
sudo ufw allow 22/tcp && sudo ufw allow in on tailscale0 && echo y | sudo ufw enable
echo 'nameserver 8.8.8.8' | sudo tee -a /etc/resolv.conf
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
source ~/.nvm/nvm.sh && nvm install 22
source ~/.nvm/nvm.sh && npm install -g openclaw@latest
"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
sleep 30
ssh -o StrictHostKeyChecking=no "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
sudo apt-get update && sudo apt-get install -y git curl ufw jq
curl -fsSL https://tailscale.com/install.sh | sh
"
These instructions make significant host changes including firewall reconfiguration, DNS modification, package installation, and service setup without a prominent warning about side effects. While not inherently malicious, this can lead users to break networking or weaken system hygiene unintentionally.
The instructions persist the Brave API key in a systemd user drop-in on disk so it survives reboots. Even with mode 600, long-lived plaintext secret storage increases the blast radius of local account compromise and may expose the key through backups or support snapshots.
# Add Brave key + enable Tailscale auth
ssh "${OPENCLAW_USERNAME}@${IP}" "
set -euo pipefail
mkdir -p ~/.config/systemd/user/openclaw-gateway.service.d
cat > ~/.config/systemd/user/openclaw-gateway.service.d/brave.conf << CONF
[Service]
Environment=\"BRAVE_API_KEY=\$(cat)\"
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
[Service]
Environment=\"BRAVE_API_KEY=\$(cat)\"
CONF
chmod 600 ~/.config/systemd/user/openclaw-gateway.service.d/brave.conf
systemctl --user daemon-reload
source ~/.nvm/nvm.sh
jq '.gateway.auth.allowTailscale = true' ~/.openclaw/openclaw.json > /tmp/oc.json
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
[Service]
Environment=\"BRAVE_API_KEY=\$(cat)\"
CONF
chmod 600 ~/.config/systemd/user/openclaw-gateway.service.d/brave.conf
systemctl --user daemon-reload
source ~/.nvm/nvm.sh
jq '.gateway.auth.allowTailscale = true' ~/.openclaw/openclaw.json > /tmp/oc.json
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
[Service]
Environment=\"BRAVE_API_KEY=\$(cat)\"
CONF
chmod 600 ~/.config/systemd/user/openclaw-gateway.service.d/brave.conf
systemctl --user daemon-reload
source ~/.nvm/nvm.sh
jq '.gateway.auth.allowTailscale = true' ~/.openclaw/openclaw.json > /tmp/oc.json
The security note is misleading because it states the gateway is exposed only via Tailscale while the instructions also explicitly allow SSH on port 22 from the public internet. Misstated security properties can cause operators to underestimate the attack surface and deploy the system with weaker monitoring and access controls.
The skill fetches and immediately executes the nvm installer from GitHub without integrity verification. This exposes the host to arbitrary code execution if the fetched content or delivery path is tampered with.
set -euo pipefail
sudo ufw allow 22/tcp && sudo ufw allow in on tailscale0 && echo y | sudo ufw enable
echo 'nameserver 8.8.8.8' | sudo tee -a /etc/resolv.conf
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
source ~/.nvm/nvm.sh && nvm install 22
source ~/.nvm/nvm.sh && npm install -g openclaw@latest
"
No suspicious patterns detected.