T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:19- Finding
Remote Installer Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill’s MiniMax search and image features are coherent, but its install path executes mutable third-party code and stores an API key in plain configuration without enough controls.
Install only if you are comfortable with MiniMax receiving your search queries and image inputs, including any local image files you ask it to analyze. Prefer a safer uv installation method, pin and verify the MCP package version, restrict the OpenClaw config file permissions, and use a limited MiniMax API key that can be rotated.
SKILL.md:19Remote Installer Is Downloaded and Executed Without Integrity Verification
SKILL.md:45Unpinned Third-Party MCP Package Is Automatically Resolved and Executed
SKILL.md:47API Key Is Stored in Plaintext OpenClaw Configuration
The specific use of '| sh' creates an unsafe command chain that executes untrusted network content without validation. In a skill installation context, this is especially dangerous because users are primed to copy-paste commands, making remote code execution straightforward if the fetched content changes or is tampered with.
# macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh
# 验证安装
which uvx
The entire skill documentation is presented only in Chinese, which effectively imposes a specific language on users without stating that the skill is Chinese-only or offering an alternative language. This can violate language/locale policy where user choice or explicit justification is required.
The image-understanding feature accepts either remote image URLs or local file paths, but the skill does not warn that image contents, file-derived data, or fetched remote resources may be transmitted to MiniMax for processing. This can lead users to expose sensitive local images or internal-only URLs without realizing the data leaves their environment.
The documentation says users can simply ask the AI to search or analyze images and that the AI will automatically invoke the MCP tools. This broad invocation guidance can cause unintentional tool use on ambiguous prompts, increasing the chance that sensitive queries, URLs, or local image paths are sent to the external MiniMax service without clear user awareness at the moment of use.
The web_search tool sends user queries to an external provider, but the skill description does not clearly disclose that fact. Users may unknowingly transmit sensitive terms, internal project names, credentials by mistake, or other private context to a third party.
The installation instructions tell users to pipe a remotely fetched script directly into the shell. If the remote endpoint, network path, or hosting account is compromised, arbitrary code will execute immediately on the user's machine with the user's privileges.
# macOS/Linux
curl -LsSf https://astral.sh/uv/install.sh | sh
# 验证安装
which uvx
No suspicious patterns detected.