T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:14- Finding
Unverified Remote Installer Is Downloaded and Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:14Complete Code Snippet:
yaml install: - id: "install-script" kind: "shell" label: "Install via script (recommended)" command: "curl -fsSL https://clawbridge.cloud/install | bash" bins: ["clawbridge"]Vulnerability Type: T03: Remote Payload Retrieval and Execution
Risk Level: High
Technical Analysis
The Skill declares an installation command that retrieves a mutable shell script from
https://clawbridge.cloud/installand pipes it directly to Bash. The payload is executed without version pinning, checksum verification, cryptographic signature validation, or an opportunity to inspect it locally.The repository contains only documentation and metadata; it does not include the installer or the resulting
clawbridgeexecutable. Consequently, the effective installation behavior cannot be audited from this package and can change after review without any corresponding update to the Skill.This is especially risky because the repository describes the installed runner as implementing the substantive workflow: building private prompts, calling OpenClaw as a worker, and uploading results to an external Vault. While the upload behavior is disclosed, the installer, runner implementation, selected data, and safeguards are not available for verification.
Direct remote script execution is not necessary for the Skill's declared thin-wrapper functionality. A pinned, independently verifiable installation artifact would provide the required executable with substantially less supply-chain risk.
Attack Path
- A user or Skill manager processes the declared shell installer.
curlrequests the current content ofhttps://clawbridge.cloud/install.- The Clawbridge server, its hosting account, DNS path, TLS termination infrastructure, or deployment pipeline is compromised—or the publisher changes the script malicio ...[truncated 1080 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the
curl | bashinstallation command from Skill metadata. - Distribute the runner through a trusted package registry or release system using immutable, versioned artifacts.
- Pin the exact package or artifact version rather than resolving the latest mutable installer.
- Publish SHA-256 or stronger checksums through an independently protected channel and verify them before execution.
- Prefer cryptographically signed releases and verify signatures against a documented, pinned publisher key.
- If a script remains necessary, download it to a local file, verify its integrity and signature, show users its source and requested changes, and require explicit confirmation before execution.
- Publish the installer and runner source, or reproducible build instructions, so their effective behavior can be audited.
- Document the runner's required filesystem, network, credential, and OpenClaw access. Run it with the minimum permissions needed for discovery and uploading.
- Avoid requiring administrator privileges. If any individual operation genuinely requires elevation, isolate and document that operation rather than elevating the entire installer.
- Remove the
