T03 · Remote Payload Retrieval and Execution
- Location
README.md:78- Finding
Unpinned Remote Payload Retrieval and Execution Through PATH
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 78-84
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash # Clone the skill git clone https://github.com/hopyky/self-reflection.git ~/.openclaw/skills/self-reflection # Add to PATH ln -sf ~/.openclaw/skills/self-reflection/bin/self-reflection ~/bin/self-reflectionTechnical Analysis
The installation instructions retrieve executable content from the mutable default branch of an external GitHub repository. They do not pin a reviewed commit or release and do not verify a cryptographic checksum or signature. The downloaded
bin/self-reflectionscript is then exposed through the user'sPATH.The executable is absent from the audited artifact, so its implementation and behavior could not be verified. The documentation subsequently instructs the agent to invoke
self-reflection checkon every heartbeat and to execute additional subcommands when an alert occurs. Consequently, the effective executable payload can differ from the content reviewed in this audit.This is best classified as remote payload retrieval and execution because mutable external code is fetched and subsequently invoked. Repository compromise, ownership changes, or malicious upstream revisions could alter the executed payload without modifying the audited package.
Attack Path
- An attacker compromises the upstream repository, its maintainer account, or otherwise causes its default branch to serve a malicious
bin/self-reflectionscript. - A user follows the documented
git clonecommand without pinning a trusted commit. - The user creates the documented symlink under
~/bin, making the remotely obtained script available throughPATH. - The OpenClaw heartbeat instructions invoke
self-reflection check; alert handling may also invokereadandlog. - The malicious script executes with the permissions and environment of the agen ...[truncated 755 chars]
- An attacker compromises the upstream repository, its maintainer account, or otherwise causes its default branch to serve a malicious
- Remediation
View remediation
Remediation Suggestions
- Include the complete
bin/self-reflectionimplementation in the reviewed skill package so that installed code matches audited code. - If remote installation remains necessary, pin the clone or checkout to a specific reviewed commit hash rather than a mutable branch.
- Publish signed releases and verify a trusted cryptographic signature before installation.
- Publish an expected SHA-256 or stronger digest through a separately trusted channel and verify it before exposing the executable through
PATH. - Avoid symlinking unverified downloads into a
PATHdirectory. Install only after explicit source review and integrity verification. - Restrict execution to the minimum required user account and ensure the process does not receive unnecessary credentials or filesystem permissions.
- Add a reproducible release process and document the exact version, commit, signature verification procedure, and expected checksum.
- Audit the missing executable before enabling recurring heartbeat execution.
- Include the complete
