T03 · Remote Payload Retrieval and Execution
- Location
README.md:23- Finding
Mutable Remote Installation Scripts Are Executed Without Verification
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This deployment skill is mostly purpose-aligned, but it asks users to run unverified remote installers, bypass OS security warnings, and enable persistent services.
Review this skill carefully before installing. Prefer manual downloads from trusted releases, verify signatures or hashes, avoid curl|bash and iwr|iex commands, do not bypass OS warnings unless you have independently verified the publisher, and store API keys with restrictive permissions. Treat service and Docker restart setup as opt-in persistence.
README.md:23Mutable Remote Installation Scripts Are Executed Without Verification
scripts/install.sh:114Unverified Executables and Floating Container Images Create a Supply-Chain Execution Risk
skill.md:318Deployment Instructions Establish Cross-Session Service and Container Persistence
scripts/install.sh:199API Keys Are Echoed and Written to Plaintext Configuration Without Enforced File Permissions
skill.md:558Instructions Encourage Users to Bypass Operating-System Application Security Warnings
curl ... | bash is a well-known dangerous chaining pattern because it turns remote network content directly into executed shell commands with no review barrier. In a deployment guide, the skill context makes this more dangerous, not less, because the documentation is explicitly designed to encourage copy-paste execution on user systems.
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
### Windows
The repeated | bash pattern in the Linux section presents the same direct remote-code-execution hazard and may be even more severe when run on Linux servers or CI/CD hosts. If the hosting account, repository, or delivery path is compromised, users executing this command can hand over full control of the target machine.
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
# 或 Docker
docker run -d -p 3000:3000 markovmodcn/nexusbot:latest
The declared description presents a comprehensive cross-platform deployment guide, explicitly including Windows and broader topics like platform integration and troubleshooting. The supplied code is instead a concrete shell installer limited to macOS and Linux. Its primary behavior is downloading and installing application packages, optionally installing Ollama by piping a remote script to sh, pulling a model, and storing API keys/config in the user's home directory. That is materially narrower and operationally different from a general guide, and the Windows support claim is clearly inaccurate.
The generic Linux path downloads a tarball discovered dynamically from release metadata, extracts it into a user directory, and exposes the resulting binary via /usr/local/bin. Without checksum/signature verification, this creates a supply-chain vector where a compromised repo, release artifact, or API response can lead to execution of attacker-controlled code.
fi
TEMP_TAR="/tmp/nexusbot-linux.tar.gz"
curl -L -o "$TEMP_TAR" "$LATEST_URL"
# 解压
echo "📦 解压..."
This line fetches a shell script from ollama.com and executes it immediately, without showing the contents, pinning a version, or asking for confirmation. That creates a direct remote code execution path and removes the user’s opportunity to review what will run on their system.
Piping curl output directly into sh is a classic dangerous chaining pattern because network-fetched content becomes immediately executable code. In the context of an installer skill, this is more dangerous than usual because users are primed to trust and run setup steps without review.
# 检查是否已安装
if ! command -v ollama &> /dev/null; then
echo "📥 安装 Ollama..."
curl -fsSL https://ollama.com/install.sh | sh
fi
# 拉取模型
The macOS section encourages overriding Gatekeeper-style protections to open the app, but does not explain the trust implications. In a public install guide, that reduces users' caution around unsigned or unverified binaries and can facilitate execution of malicious software.
The guide includes a remote shell script piped directly to bash with no warning about trust, code review, or host modification. Because this is a deployment skill, users are likely to copy-paste it verbatim, making arbitrary code execution risk more acute.
The | bash construction chains network retrieval directly into shell execution, eliminating any review boundary. In a skill intended for copy-paste deployment, this materially raises the risk of arbitrary code execution and supply-chain compromise.
# 一键安装脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
The PowerShell one-liner downloads and executes remote code immediately without warning. This is especially risky on Windows because it collapses download, trust, and execution into one step, leaving no opportunity for validation.
The Linux instructions include curl ... | bash without explaining that it executes untrusted remote code and may alter the system. In a deployment guide, this creates a realistic path to arbitrary command execution if the source is compromised.
The Linux one-liner pipes a remote install script straight into bash, which is a classic unsafe execution chain. If the remote content is malicious or tampered with, the user grants immediate code execution on the host.
# 一键安装脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
curl -fsSL https://ollama.com/install.sh | sh downloads and executes a remote script in one step. This creates direct arbitrary code execution risk if the script source, hosting, DNS, or transport trust is compromised.
# 一键安装
curl -fsSL https://ollama.com/install.sh | sh
The | sh Ollama installer is another direct fetch-and-execute chain. This is dangerous because it combines retrieval and execution of remote content into a single blind action with no verification step.
# 一键安装
curl -fsSL https://ollama.com/install.sh | sh
The troubleshooting section tells users to remove the quarantine attribute from a macOS app without discussing the loss of platform protections. This increases the chance of users running unverified software and undermines OS security expectations.
The README instructs users to fetch a remote shell script and immediately execute it with bash, with no warning, verification step, or integrity check. This creates a direct remote-code-execution path on the user's machine and is especially dangerous in a deployment guide because users are likely to copy-paste commands verbatim.
The PowerShell command downloads remote content and passes it directly to iex, which executes it immediately in memory. This is a classic high-risk pattern that enables silent execution of attacker-controlled code if the source is compromised, redirected, or tampered with.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu/Debian
wget https://github.com/Markovmodcn/openclaw-china/releases/latest/download/nexusbot_amd64.deb
sudo dpkg -i nexusbot_amd64.deb
# 或一键脚本
curl -fsSL https://raw.githubusercontent.com/Markovmodcn/openclaw-china/main/scripts/install.sh | bash