T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned and Unverified Remote Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 31-37
Vulnerability Type: Supply-chain exposure through mutable, unverified remote content
Risk Level: Mediumbash # Clone the repo git clone https://github.com/KaigeGao1110/Project-Coordinator.git ~/.openclaw/skills/project-coordinator # Or download directly curl -L https://github.com/KaigeGao1110/Project-Coordinator/archive/refs/heads/main.zip -o /tmp/project-coordinator.zip unzip /tmp/project-coordinator.zip -d ~/.openclaw/skills/ mv ~/.openclaw/skills/Project-Coordinator-main ~/.openclaw/skills/project-coordinatorTechnical Analysis
Both installation methods retrieve the mutable default branch from a personal GitHub repository. Neither method pins an audited commit or immutable release, and the instructions do not verify a checksum or cryptographic signature.
The downloaded ZIP is not directly executed by these commands. However, it is extracted into the OpenClaw skills directory, where its contents can subsequently be loaded as Agent instructions. The effective behavior installed on a user's system can therefore differ from the content reviewed during this audit.
This creates a time-of-check to time-of-use supply-chain risk. If the upstream repository is compromised or its default branch is modified, future users may install altered Skill instructions or additional files without an integrity check detecting the change.
Attack Path
- An attacker compromises the upstream repository, its maintainer account, or the content served for the mutable
mainbranch. - The attacker adds malicious Skill instructions or executable components to the repository.
- A user follows the documented
git cloneorcurlinstallation procedure. - The altered content is installed without commit pinning, signature verification, or checksum validation.
- OpenClaw subsequently loads the attacker-controlled Skill.
- The malicious content can ...[truncated 944 chars]
- An attacker compromises the upstream repository, its maintainer account, or the content served for the mutable
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
mainreference with an immutable, audited commit hash or versioned release artifact. - Publish a SHA-256 digest for every release and verify it before extraction.
- Prefer signed release artifacts and verify the signature against a documented maintainer key.
- For Git installation, explicitly check out the approved commit and verify the resulting commit identifier.
- Fail closed if integrity or signature validation fails.
- Keep the front-matter version, embedded manifest version, README badge, and installation artifact version synchronized to improve provenance.
- Prefer a trusted registry installation path only when the registry provides package provenance, immutable version resolution, and signature or integrity verification.
- Replace the mutable
