T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:277- Finding
Unverified Remote Installer Is Streamed Directly Into Command Interpreters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be legitimate OpenClaw maintenance documentation, but it recommends unsafe install/update commands and a troubleshooting step that can expose secrets.
Review the install and update commands before using this skill. Prefer pinned packages or downloaded installers with checksum/signature verification, avoid running network responses directly through a shell, and do not let an agent print or paste ~/.openclaw/.env or other credential files. Treat daemon, cron, plugin, browser, and remote-access setup as privileged administrative actions that should remain under explicit user control.
SKILL.md:277Unverified Remote Installer Is Streamed Directly Into Command Interpreters
install.md:40Mutable Package Versions and Executable Lifecycle Scripts Create Supply-Chain Risk
gateway_ops.md:290Troubleshooting Procedure Prints the Entire Secrets Environment File
Referencing openclaw update in an operational skill exposes a self-modification path where the managed software can change version, behavior, or dependencies during a support flow. In an autonomous or semi-autonomous agent context, self-updates are risky because they can introduce unreviewed code changes and destabilize the environment mid-session.
openclaw channels status --probe # Channel health check
openclaw security audit # Security posture check
openclaw security audit --fix # Auto-fix security issues
openclaw update # Self-update
openclaw dashboard # Open Control UI in browser
openclaw tui # Terminal UI (interactive REPL)
openclaw agent # Direct agent interaction via CLI
curl -fsSL https://openclaw.ai/install.sh | bash fetches remote content and immediately executes it without local inspection, signature verification, or pinning. This is dangerous because compromise of the remote host, TLS interception edge cases, or supply-chain tampering could result in arbitrary code execution on the operator's machine.
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash
# Update
openclaw update # Self-update command
The | bash pattern is a classic command-chaining hazard because it converts network input directly into shell execution in one step. In an agent skill, this is especially dangerous because it reduces opportunities for human review and makes accidental or automated arbitrary code execution more likely.
# Install (recommended)
curl -fsSL https://openclaw.ai/install.sh | bash
# Update
openclaw update # Self-update command
This section combines installation/update guidance with direct upgrade commands, including self-update and package-manager upgrade paths, making code and dependency changes a first-class recommended action. In agent-driven maintenance workflows, this materially increases the chance of unreviewed self-modification or environment drift, especially if invoked as a generic fix step.
curl -fsSL https://openclaw.ai/install.sh | bash
# Update
openclaw update # Self-update command
# Or: npm install -g openclaw@latest
openclaw doctor # Run after update to apply migrations
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
| Endpoint | Description |
|---|---|
| `GET /`, `POST /start`, `POST /stop` | Status/start/stop |
| `GET /tabs`, `POST /tabs/open`, `POST /tabs/focus`, `DELETE /tabs/:targetId` | Tab control |
| `GET /snapshot`, `POST /screenshot` | Snapshot/screenshot |
| `POST /navigate`, `POST /act` | Navigation and actions |
| `POST /hooks/file-chooser`, `POST /hooks/dialog` | Hooks |
This pattern attempts to override system instructions or ignore safety constraints. Without LLM analysis, manual review is recommended.
# Step 3: Generate invite URL with scopes: bot, applications.commands
# Permissions: View Channels, Send Messages, Read Message History, Embed Links, Attach Files
# Step 4: Enable Developer Mode
# User Settings → Advanced → Developer Mode → On
# Right-click server → Copy Server ID
# Right-click avatar → Copy User ID
The document instructs users to fetch and execute a remote script directly from the network. This creates a strong supply-chain risk because any compromise of the source, CDN, DNS, or TLS termination can turn installation into arbitrary code execution on the user's machine.
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash
# npm
npm install -g openclaw@latest
The | bash pipeline turns an external network response directly into shell execution, eliminating any review boundary and making exploitation immediate if the upstream content is malicious or tampered with. In a gateway administration guide, this is especially dangerous because operators are likely to run it on privileged or always-on hosts.
# Installer script (macOS / Linux)
curl -fsSL https://openclaw.ai/install.sh | bash
# npm
npm install -g openclaw@latest
The instructions recommend cat ~/.openclaw/.env, which can print live API keys and tokens directly to the terminal, shell history capture tools, logs, screen shares, or support transcripts. Because this skill concerns a gateway handling multi-channel integrations, the .env file likely contains sensitive credentials whose disclosure can enable account takeover or service abuse.
# 1. Validate the config
openclaw config validate
# 2. Check .env has real values (no placeholders)
cat ~/.openclaw/.env
# 3. Full restart (not just hot-reload)
This finding is part of the same unsafe guidance to display the entire .env contents for validation. Exposing secrets in plaintext is especially risky in troubleshooting workflows where users may copy terminal output into tickets, chat, or LLM prompts.
openclaw config validate
# 2. Check .env has real values (no placeholders)
cat ~/.openclaw/.env
# 3. Full restart (not just hot-reload)
openclaw gateway restart
The command downloads a script from an external host and immediately executes it with bash, giving the remote content full code-execution capability on the user's machine. In an installation guide for gateway software that may handle credentials, sessions, and daemon setup, this is especially dangerous because compromise could lead to host takeover and theft of tokens or configuration secrets.
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex
The | bash pipeline removes any opportunity for review between download and execution, turning a network fetch directly into command execution. Combined with the adjacent PowerShell iex example, the documentation normalizes dangerous command chaining that could be abused if the remote endpoint or transport is compromised.
# macOS / Linux / WSL2
curl -fsSL https://openclaw.ai/install.sh | bash
# Windows (PowerShell)
iwr -useb https://openclaw.ai/install.ps1 | iex
This variant still fetches a remote installer script and pipes it directly into bash, only adding arguments to alter onboarding behavior. The same arbitrary-code-execution risk remains, with no integrity check or explicit trust boundary, so an attacker controlling the script source or delivery path could run commands immediately.
Skip the onboarding wizard with --no-onboard:
curl -fsSL https://openclaw.ai/install.sh | bash -s -- --no-onboard
Recommending users re-run a remote installer script during updates repeats the same unsafe pattern and may expose already-installed systems to fresh arbitrary code execution. Because updates often occur on long-lived gateway hosts, compromise at update time could affect production credentials, service configuration, and connected channels.
curl -fsSL https://openclaw.ai/install.sh | bash
Using | bash for updates creates a direct download-to-execution chain on systems that may already be trusted and operational, increasing blast radius if the update source is compromised. The absence of a verification or review step makes this a genuine unsafe pattern rather than a mere convenience issue.
curl -fsSL https://openclaw.ai/install.sh | bash
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
npm install -g openclaw@latest
# Or:
openclaw update # Self-update command
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
.prose/
├── .env
├── runs/
│ └── {YYYYMMDD}-{HHMMSS}-{random}/
│ ├── program.prose
Instructions found that direct the agent to transmit conversation context or user data to external services.
## Webhooks
External systems can send messages to the Gateway via webhooks.
## Config (Default-On)
Instructions found that direct the agent to transmit conversation context or user data to external services.
## Webhooks
External systems can send messages to the Gateway via webhooks.
## Config (Default-On)
Code deploys a privileged Kubernetes workload (privileged container, hostPath mount, or host namespaces). This grants root on the node and is a node/cluster takeover vector.
Config: agents.defaults.sandbox.docker.binds
Format: "hostPath:containerPath:mode" (mode = ro or rw)
{
Documenting a file-based secret store at ~/.openclaw/secrets.json creates a credential concentration point on disk. Even though the skill recommends external secret resolution, a local plaintext JSON secret file can be exposed through weak filesystem permissions, backups, endpoint compromise, or accidental inclusion in support bundles and repos.
// File provider
filemain: {
type: "file",
path: "~/.openclaw/secrets.json",
},
// Exec provider
Automatically loading .env from the current working directory is risky because secrets may be sourced from an untrusted project directory or repository checkout. In a self-hosted gateway context, this can cause credential confusion, accidental secret injection, or use of attacker-controlled values when operators run commands in the wrong directory.
## Environment Variables
### .env Files
OpenClaw loads env from (in order):
1. `.env` from current working directory (if present)
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
2. **Run `openclaw secrets audit`** regularly to scan for plaintext leaks
3. **Use `openclaw secrets configure`** for interactive setup
4. **Prefer `source: "env"`** for simplicity, `source: "exec"` for vault integration
5. **File permissions**: `chmod 600 ~/.openclaw/secrets.json`
6. **Rotate secrets** immediately if you suspect compromise
Instructions found that direct the agent to transmit conversation context or user data to external services.
- Execute arbitrary shell commands
- Read/write files
- Access network services
- Send messages to anyone (if given WhatsApp access)
A malicious external actor can:
- Try to trick your AI into doing bad things
Instructions found that direct the agent to transmit conversation context or user data to external services.
| `/subagents kill <id\|#\|all>` | Stop a sub-agent (or all) |
| `/subagents log <id\|#> [limit] [tools]` | View sub-agent transcript |
| `/subagents info <id\|#>` | Detailed sub-agent info |
| `/subagents send <id\|#> <message>` | Send message to sub-agent |
| `/subagents steer <id\|#> <message>` | Nudge sub-agent without replacing context |
| `/subagents spawn <agentId> <task>` | Spawn new sub-agent (one-shot `mode: "run"`) |
Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions, suspicious.secret_argv_exposure