T03 · Remote Payload Retrieval and Execution
- Location
references/runtime-requirements.md:34- Finding
Automatic Retrieval and Execution of Mutable Third-Party Code
- Content
View full analysis
Vulnerability Details
File Location:
references/runtime-requirements.md:34-82
Additional Location:SKILL.md:34-39
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighTechnical Analysis
The skill instructs the agent to clone the
social-auto-uploadrepository automatically and, if the canonical GitHub source is unavailable, retry through an unofficial Gitee fork and multiple proxy services. The retrieved repository is not pinned to a reviewed commit, tag, or cryptographic digest.Relevant instructions include:
bash git clone https://github.com/dreammis/social-auto-upload.git "$HOME/.openclaw/social-auto-upload" # Attempt 1: Gitee mirror git clone https://gitee.com/lonycn/social-auto-upload.git <SAU_HOME> # Attempt 2: gh-proxy.org git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git <SAU_HOME> # Attempt 3: gh-proxy.com git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME> # Attempt 4: gitmirror git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>The downloaded project is subsequently used as the execution environment:
bash uv sync --python 3.12 uv run --project <SAU_HOME> python sau_cli.py --helpBecause no commit identity, signed tag, or content hash is validated, the effective code executed by the skill can change after the skill package itself has been reviewed. The Gitee URL also refers to a separately controlled repository rather than a cryptographically authenticated representation of the canonical repository.
Attack Path
- An attacker compromises one of the configured repositories or proxy delivery paths, or controls the unofficial mirror.
- The canonical GitHub clone fails or times out.
- Following the skill instructions, the agent automatically retries the configured mirro ...[truncated 1078 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the upstream project to a specifically reviewed commit hash rather than cloning the mutable default branch.
- Verify the checked-out commit before running dependency installation or any Python entry point.
- Use only the canonical repository unless each mirror is authenticated and proven to provide byte-for-byte identical Git objects.
- Remove the unofficial Gitee fork from automatic fallback handling.
- Where possible, distribute a reviewed, immutable source archive with a published SHA-256 digest or vendor the necessary code into the skill package.
- Require explicit user confirmation before first-time retrieval and execution of external code.
- Run the external uploader in a sandbox with access limited to the selected media files and a dedicated credential directory.
- Treat an existing checkout as untrusted until its remote URL and current commit have both been validated.
