T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:21- Finding
Unverified Remote Installer Executed Directly Through Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 21
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code:
markdown - Install: `curl -fsSL https://imans.ai/install | bash`Technical Analysis
The installation command retrieves a shell script from a mutable external URL and passes it directly to Bash. It does not pin a release version, verify a cryptographic checksum or signature, or provide an opportunity to inspect the script before execution.
Although HTTPS protects the response in transit under normal conditions, it neither proves the integrity of the underlying installer across time nor constrains what the script may do. The effective payload can change after the Skill has been reviewed. Compromise of the website, hosting account, DNS infrastructure, TLS endpoint, or installer publication process could therefore turn this instruction into an arbitrary-code-execution channel.
Executing an installer is not necessary for the Skill's declared runtime functionality of querying Imans data. The document already identifies Homebrew and downloadable GitHub releases as alternative installation mechanisms. Direct execution of an unverified remote script consequently exceeds the minimum trust and execution privileges required to obtain the CLI.
The remote installer was not included in the audited project, so its current contents and behavior cannot be established from the available evidence. No claim is made that it presently installs persistence, escalates privileges, or exfiltrates credentials.
Attack Path
- An attacker compromises or gains control over
https://imans.ai/installor an infrastructure component capable of altering its response. - The attacker replaces the expected installer with malicious shell commands.
- A user or OpenClaw operator follows the documented installation instruction.
curldownloads the attacker-controlled response ...[truncated 894 chars]
- An attacker compromises or gains control over
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation instruction. - Direct users to a specific, version-pinned release from the declared GitHub repository rather than a mutable “latest” installer endpoint.
- Publish SHA-256 or stronger checksums through a separately protected release channel and require verification before installation.
- Prefer cryptographically signed release artifacts and document signature verification using a pinned, trusted signing key.
- If a shell installer remains available, instruct users to download it to a file, verify its integrity, inspect it, and only then execute it.
- Run installation with ordinary user privileges unless a narrowly identified operation strictly requires elevation. Avoid executing the entire installer as root.
- Document the installer's expected filesystem changes, network destinations, and required permissions so operators can evaluate its scope.
- Pin the Homebrew formula or release version where reproducibility is required, and ensure the distribution pipeline is protected with restricted release permissions and strong authentication.
A safer documented workflow would resemble:
bash curl -fLO https://github.com/imans-ai/imans-cli/releases/download/vX.Y.Z/IMANS_ARTIFACT echo "EXPECTED_SHA256 IMANS_ARTIFACT" | sha256sum --check - # Install the verified artifact using the documented least-privilege procedure.The actual version, artifact name, checksum, and installation procedure must come from a trusted, maintained release process.
- Remove the
