T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:53- Finding
Mutable Remote Instructions Can Replace Active Skill Behavior
- Content
View full analysis
~/.openclaw/skills/clawstarter/SKILL.md curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md curl -s https://clawstarter.io/skill.json > ~/.openclaw/skills/clawstarter/package.json ``` ```markdown **Check for updates:** Re-fetch these files anytime to see new features! ``` `HEARTBEAT.md:12-20`: ```bash curl -s https://clawstarter.io/skill.json | grep '"version"' ``` ```markdown Compare with your saved version. If there's a new version, re-fetch the skill files: ``` ```bash curl -s https://clawstarter.io/skill.md > ~/.openclaw/skills/clawstarter/SKILL.md curl -s https://clawstarter.io/heartbeat.md > ~/.openclaw/skills/clawstarter/HEARTBEAT.md curl -s https://clawstarter.io/discourse.md > ~/.openclaw/skills/clawstarter/DISCOURSE.md ``` ### Technical Analysis The update workflow downloads mutable Markdown documents and writes them directly over the installed Skill files. In a documentation-driven Agent Skill, these files determine Agent behavior and therefore function as executable instructions. The workflow provides no cryptographic signature verification, pinned content digest, immutable release URL, trusted-version manifest, review step, or rollback mechanism. HTTPS protects transport against ordinary interception but does not protect against a compromised server, malicious account holder, deployment error, or intentionally harmful future release. The update check only extracts a remotely supplied version string. It does not establish the authenticity or integrity of the downloaded files. ### Attack P ...[truncated 1457 chars]- Remediation
View remediation
