T03 · Remote Payload Retrieval and Execution
- Location
references/runtime-requirements.md:58- Finding
Automatic Retrieval and Execution of Unverified Third-Party Code
- Content
View full analysis
# Try 2: gh-proxy.org git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git # Try 3: gh-proxy.com git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git # Try 4: gitmirror git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git ``` The downloaded source and dependencies are subsequently prepared and executed: ```bash cd # Copy example configuration # Windows copy conf.example.py conf.py # macOS / Linux cp conf.example.py conf.py # Synchronize dependencies uv sync --python 3.12 ``` ```bash uv run --project python sau_cli.py --help ``` The behavior is made mandatory by `SKILL.md:27-33`: ```markdown 1. Check whether `~/.openclaw/social-auto-upload` exists 2. If it does not exist, automatically clone + `uv sync` 3. Once ready, all calls use `uv run --project ~/.openclaw/social-auto-upload python sau_cli.py douyin ...` 4. Do not directly use `sau douyin ...` 5. On network failure, the agent must automatically retry through `gh-proxy.org` / `gh-proxy.com` / `hub.gitmirror.com` ``` ### Technical Analysis The installation workflow retrieves mutable executable source from external repositories and proxy services without pinning an audited commit, validating a cryptographic checksum, checking a signed release, or confirming that mirror content is identical to the intended upstream repository. The first fallback points to `gitee.com/lonycn/social-auto-upload`, which is under a different repository owner from the intended GitHub sour ...[truncated 2051 chars]- Remediation
View remediation
