T03 · Remote Payload Retrieval and Execution
- Location
references/embedding-setup.md:13- Finding
Unverified Remote Script Download and Immediate Shell Execution
- Content
View full analysis
Vulnerability Details
File Location:
references/embedding-setup.md:13-19
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: CriticalVulnerable Code:
bash ### 1. Install Ollama ```bash curl -fsSL https://ollama.ai/install.sh | shOr download from ollama.ai.
text ### Technical Analysis The installation instructions pipe content retrieved from an external URL directly into a shell. The downloaded script is not pinned to a reviewed version, saved for inspection, or validated through a cryptographic signature or checksum. Consequently, the effective code executed by this instruction can change after the Skill package has been reviewed. Compromise of the remote server, its publishing process, DNS resolution, or the TLS trust chain could substitute arbitrary shell commands. Installing Ollama is not required for the Skill's core rule-based memory-routing functionality because the documentation explicitly supports operation without vector embeddings. Immediate remote shell execution therefore exceeds the minimum privileges necessary for the declared core functionality. ### Attack Path 1. An attacker compromises the remote installation-script host, publishing process, or relevant network trust path. 2. The attacker modifies the content returned by `https://ollama.ai/install.sh`. 3. A user follows the documented installation command. 4. `curl` retrieves the attacker-controlled content. 5. The pipe sends the content directly to `sh` without inspection or integrity verification. 6. The payload executes with all privileges available to the invoking user and may request or invoke elevated installation operations. ### Impact Assessment Successful exploitation provides arbitrary command execution under the invoking account. The payload could read or alter workspace files, OpenClaw configuration, persistent memory, credentials accessible to the us ...[truncated 255 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | shinstallation pattern. - Direct users to an official, version-pinned release artifact.
- Require verification using a publisher-provided cryptographic signature or SHA-256 checksum.
- Download the installer to a local file and instruct users to inspect it before execution.
- Document the expected filesystem and privilege changes made by the installer.
- Explicitly state that embeddings are optional and that the Skill can operate without installing Ollama.
- Prefer operating-system package managers with signed repositories where available.
- Do not recommend running the installer with elevated privileges unless a specific operation demonstrably requires them.
- Remove the
