T03 · Remote Payload Retrieval and Execution
- Location
references/runtime-requirements.md:38- Finding
Unverified Remote Source Fallback Is Installed and Executed
- Content
View full analysis
Vulnerability Details
File Location:
references/runtime-requirements.md:38-71, 84-94, 101-112, 121-139; also mandated bySKILL.md:41-46
Vulnerability Type: Unverified remote payload retrieval and supply-chain execution
Risk Level: CriticalVulnerable Code
bash # Direct upstream git clone https://github.com/dreammis/social-auto-upload.git <SAU_HOME> # Automatic fallbacks git clone https://gitee.com/lonycn/social-auto-upload.git <SAU_HOME> git clone https://gh-proxy.org/https://github.com/dreammis/social-auto-upload.git <SAU_HOME> git clone https://gh-proxy.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME> git clone https://hub.gitmirror.com/https://github.com/dreammis/social-auto-upload.git <SAU_HOME>The downloaded project is subsequently installed and executed:
bash cd <SAU_HOME> cp conf.example.py conf.py uv sync --python 3.12bash uv run --project <SAU_HOME> python sau_cli.py --helpA browser binary is also downloaded through a third-party mirror:
bash PLAYWRIGHT_DOWNLOAD_HOST="https://npmmirror.com/mirrors/playwright" \ uv run --project "$HOME/.openclaw/social-auto-upload" patchright install chromiumTechnical Analysis
The setup workflow requires the agent to retrieve executable source code at runtime and execute it without pinning or verifying an immutable revision. The fallback Gitee repository belongs to
lonycn, rather than the declared upstream ownerdreammis. The other fallback URLs route source retrieval through third-party proxy or mirror services.No required control verifies a commit hash, signed tag, repository identity, source archive checksum, or downloaded browser digest. Consequently, the effective code can change after this Skill has been reviewed. A compromised fork, mirror, proxy, upstream branch, or associated dependency metadata could provide a modified
pyproject.toml, lockfile, build component, orsau_cli.py.Running
uv syncprocesses dependenc ...[truncated 1784 chars]- Remediation
View remediation
Remediation Suggestions
- Remove the unrelated Gitee fork and untrusted proxy or mirror fallbacks.
- Retrieve source only from the declared upstream repository over authenticated HTTPS.
- Pin a specifically audited, immutable commit and verify
HEADagainst the expected full commit hash before running any setup command. - Require signed-tag or signed-commit verification where the upstream supports it.
- Verify the expected repository origin and reject unexpected owners, remotes, redirects, or repository identities.
- Validate the reviewed lockfile before dependency synchronization and use locked/frozen dependency resolution.
- Audit build backends and dependency installation behavior before allowing project setup.
- Verify browser artifacts against cryptographic hashes published through a trusted, independent channel.
- Require explicit user approval before downloading and executing remote software.
- Prefer vendoring a reviewed source snapshot and verified dependencies when reproducible source verification cannot be guaranteed.
- Run the external automation in a restricted environment with minimal filesystem access and no unnecessary credentials.
