T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:29- Finding
Unpinned Remote Installer Is Executed Directly by Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This appears to be a real Feishu bot configuration helper, but it needs review because it asks for bot secrets in chat, installs mutable remote code, and creates broad bot access by default.
Install only after reviewing the installer and preferably pinning it to a trusted commit. Do not paste production Feishu App Secrets into chat or logs unless you accept that retention risk. Before running the configurator, back up openclaw.json, review the generated agent permissions, replace wildcard allowFrom with explicit trusted users, avoid skills all unless required, and plan for Gateway restart downtime.
SKILL.md:29Unpinned Remote Installer Is Executed Directly by Bash
install.sh:17Installer Clones Mutable Supply-Chain Content and Runs npm Install
scripts/auto-configure-bot.js:252Wildcard Direct-Message Access and Open Group Policy Expose Configured Agents
README.md:61Realistic Feishu App Secret Is Embedded in Documentation
The skill explicitly instructs users to submit App ID and App Secret directly in chat-based configuration messages. In this context, chat transcripts, agent logs, prompt history, and downstream reporting may retain those credentials, creating a direct path to credential disclosure and unauthorized control of the Feishu bot integration.
Using '| bash' chains network retrieval directly into shell execution, eliminating opportunities for inspection or validation before code runs. In this skill's context, the command is presented as the primary installation path for an automation tool that changes bot configuration and restarts infrastructure, which amplifies the risk of host compromise and unauthorized operational changes.
curl -fsSL https://raw.githubusercontent.com/jiebao360/feishu-bot-config-helper/main/install.sh | bash
Skill contains instructions that could directly expose system prompts, internal rules, or hidden instructions to users or external parties.
for (const rule of rules) {
for (const keyword of rule.keywords) {
if (nameLower.includes(keyword.toLowerCase())) {
return rule;
}
}
}
The changelog states that the system will automatically update openclaw.json and restart the gateway, but does not indicate safeguards, authorization checks, confirmation steps, or user-visible warnings. In an auto-configuration feature, undocumented config mutation and service restarts are security-relevant because they can enable unauthorized operational changes, disrupt availability, or apply attacker-influenced settings if upstream inputs are not tightly controlled.
The changelog documents keyword-based agent routing using broad, everyday terms like '内容', '通用', '工作', and '助手'. In a chat-driven bot configuration context, these overlapping triggers can cause users or attackers to unintentionally or deliberately select the wrong agent, leading to misrouting of conversations, incorrect workspace/memory isolation, or unintended capability exposure.
The README advertises automatic updates to openclaw.json and automatic Gateway restarts without any warning, confirmation, rollback guidance, or scope limitation. In an agent skill context, undocumented system-changing actions can surprise operators and lead to unsafe configuration drift or service disruption if triggered from chat-driven input.
The documentation includes plaintext App Secret examples and does not warn users to treat them as credentials or avoid sharing real secrets in chat, logs, screenshots, or examples. This normalizes unsafe secret handling and increases the chance that operators will paste production credentials into conversational channels that may be stored or observed.
The sample report echoes back user-supplied configuration details and presents that pattern as normal post-setup behavior. Even though the example visibly shows only App ID, the documented workflow elsewhere collects App Secret, so reporting conventions that reflect input values increase the risk that secrets will be echoed, logged, or exposed in operator-visible output.
The skill advertises automatic Agent creation, workspace configuration, file updates, and Gateway restarts without an explicit upfront warning about these side effects or their operational impact. In a skill context, undisclosed state-changing behavior can cause administrators to run it without understanding that it will alter configuration and disrupt service availability.
The installer clones code from a remote GitHub repository and immediately runs npm install, which can execute lifecycle scripts from the downloaded package and its dependencies. This creates a real supply-chain and remote-code-execution risk, especially because the script provides no warning, integrity verification, pinning, or review step before executing untrusted external code.
The header comment says the script supports directly configuring a new bot and automatically creating an Agent, workspace, and bindings. However, in addAgent the code checks for an existing agent ID and updates that agent's name, workspace, and skills when present, which is a materially different action from only creating a new bot configuration.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
return;
}
exec(`mkdir -p "${workspacePath}"`, (error) => {
if (error) {
console.error('❌ 创建工作空间失败:', error.message);
} else {
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
return;
}
exec(`mkdir -p "${workspacePath}"`, (error) => {
if (error) {
console.error('❌ 创建工作空间失败:', error.message);
} else {
The script writes credentials into the main configuration and restarts the gateway immediately, with no confirmation, dry-run, or rollback step. In an agent-skill context, that makes a single supplied message capable of persistently changing bot routing and service state, increasing the risk of unauthorized or accidental reconfiguration.
All user-facing natural-language content in this file is Chinese, and there is no indication that language selection is optional or that the skill is intentionally limited to a Chinese-speaking context. This may conflict with a language/locale policy requiring user opt-in or documented justification for locale constraints.
The entire skill document is written in Chinese and presents the skill as a general-purpose configuration assistant, but it does not indicate that Chinese is optional or that the skill is intended only for a Chinese-speaking or region-specific audience. Under the policy, forcing a specific language without opt-in can be a natural-language policy violation.
The skill instructs users to fetch and execute a remote script directly from GitHub using curl piped to bash. This is dangerous because the downloaded content is not pinned, verified, or reviewed locally, so any repository compromise, malicious update, or network-layer tampering could lead to immediate arbitrary code execution on the user's machine.
curl -fsSL https://raw.githubusercontent.com/jiebao360/feishu-bot-config-helper/main/install.sh | bash
The script's prompts and usage text are entirely in Chinese, which imposes a specific language on all users without offering an alternative or documenting that the skill is intended only for Chinese-speaking users. This matches the policy concern for language or locale constraints without user opt-in.
Natural-language parsing in this skill depends on Chinese phrases such as '配置飞书机器人:' and '创建技能', and the user-facing help/output is also Chinese-only. That enforces a specific language/locale behavior without any opt-in or alternative, which conflicts with the language-choice policy.
generateReport always says '✅ 添加路由绑定' was completed. In addBinding, if a matching binding already exists, the function logs that it is skipping the operation and returns false, so the report can contradict the actual behavior.
The report always states '✅ 创建工作空间目录' as a completed action. But createWorkspace resolves successfully both when it creates the directory and when it merely finds an existing workspace, so the report can assert creation that never happened.
Detected: suspicious.dangerous_exec