Back to skill

Security audit

Imans Claw

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent for querying Imans data, but its setup instructions include an unsafe remote installer command that would execute mutable code directly in a shell.

Review this skill before installing. Prefer the Homebrew or GitHub release installation path, and avoid running the documented `curl | bash` command unless you independently trust and verify the installer. Use least-privilege Imans profiles and confirm before allowing broad exports of order or customer data.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:21
Finding

Unverified Remote Installer Executed Directly Through Bash

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 21
Vulnerability Type: Remote payload retrieval and execution
Risk Level: High

Vulnerable Code:

markdown
- Install: `curl -fsSL https://imans.ai/install | bash`

Technical Analysis

The installation command retrieves a shell script from a mutable external URL and passes it directly to Bash. It does not pin a release version, verify a cryptographic checksum or signature, or provide an opportunity to inspect the script before execution.

Although HTTPS protects the response in transit under normal conditions, it neither proves the integrity of the underlying installer across time nor constrains what the script may do. The effective payload can change after the Skill has been reviewed. Compromise of the website, hosting account, DNS infrastructure, TLS endpoint, or installer publication process could therefore turn this instruction into an arbitrary-code-execution channel.

Executing an installer is not necessary for the Skill's declared runtime functionality of querying Imans data. The document already identifies Homebrew and downloadable GitHub releases as alternative installation mechanisms. Direct execution of an unverified remote script consequently exceeds the minimum trust and execution privileges required to obtain the CLI.

The remote installer was not included in the audited project, so its current contents and behavior cannot be established from the available evidence. No claim is made that it presently installs persistence, escalates privileges, or exfiltrates credentials.

Attack Path

  1. An attacker compromises or gains control over https://imans.ai/install or an infrastructure component capable of altering its response.
  2. The attacker replaces the expected installer with malicious shell commands.
  3. A user or OpenClaw operator follows the documented installation instruction.
  4. curl downloads the attacker-controlled response ...[truncated 894 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the curl | bash installation instruction.
  2. Direct users to a specific, version-pinned release from the declared GitHub repository rather than a mutable “latest” installer endpoint.
  3. Publish SHA-256 or stronger checksums through a separately protected release channel and require verification before installation.
  4. Prefer cryptographically signed release artifacts and document signature verification using a pinned, trusted signing key.
  5. If a shell installer remains available, instruct users to download it to a file, verify its integrity, inspect it, and only then execute it.
  6. Run installation with ordinary user privileges unless a narrowly identified operation strictly requires elevation. Avoid executing the entire installer as root.
  7. Document the installer's expected filesystem changes, network destinations, and required permissions so operators can evaluate its scope.
  8. Pin the Homebrew formula or release version where reproducibility is required, and ensure the distribution pipeline is protected with restricted release permissions and strong authentication.

A safer documented workflow would resemble:

bash
curl -fLO https://github.com/imans-ai/imans-cli/releases/download/vX.Y.Z/IMANS_ARTIFACT
echo "EXPECTED_SHA256  IMANS_ARTIFACT" | sha256sum --check -
# Install the verified artifact using the documented least-privilege procedure.

The actual version, artifact name, checksum, and installation procedure must come from a trusted, maintained release process.

Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

External Script Fetching

High
Category
Supply Chain
Confidence
94% confidence
Finding

The skill recommends installing software via curl ... | bash, which executes a remote script directly in the user's shell without prior inspection or integrity verification. If the upstream site, network path, or installation endpoint is compromised, this can lead to arbitrary code execution on the host where the agent or user follows the setup instructions.

Content

Scanner excerpt · SKILL.md (reported line 21)May include surrounding context.

md
## Imans Setup

- Install: `curl -fsSL https://imans.ai/install | bash`
- Homebrew: `brew install imans-ai/tap/imans`
- Verify: `imans version`
- Login interactively: `imans login`

Static analysis

No suspicious patterns detected.