T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:177- Finding
Arbitrary Remote Skill Retrieval and Activation Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 177–185
Vulnerability Type: Unverified remote payload retrieval and archive extraction
Risk Level: HighVulnerable Code
bash # Download/copy to the target path if [[ "<source>" =~ ^https?:// ]]; then curl -L "<source>" | tar -xz -C "<target-skills-dir>/" else cp -r "<source>" "<target-skills-dir>/<skill-name>" fi # Mark as manually installed touch "<target-skills-dir>/<skill-name>/.manual-install"Technical Analysis
The documented installation workflow accepts an arbitrary HTTP or HTTPS URL, follows redirects with
curl -L, and streams the response directly intotar. The resulting files are extracted into a configured Skill directory without:- Restricting downloads to trusted domains or registries.
- Requiring HTTPS after redirects.
- Pinning an expected version or cryptographic digest.
- Verifying a publisher signature.
- Staging and reviewing the archive before installation.
- Validating archive entries for absolute paths, symbolic-link abuse, or
../path traversal. - Disabling the newly installed Skill until explicit approval.
Because the destination is a Skill-loading directory, attacker-controlled Skill instructions or executable content can become available to OpenClaw after installation. The broader workflow also enables directory watching and instructs the operator to restart the gateway after adding a Skill space, increasing the likelihood that newly imported content will be loaded.
Directly piping network input into an archive extractor also prevents meaningful verification before files are written. A malicious archive may attempt to place files outside the intended Skill directory if archive-path and link validation are not enforced.
Attack Path
- An attacker supplies or recommends an attacker-controlled URL as the manual Skill installation so ...[truncated 1343 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove support for arbitrary URL installation where possible and require installation through a trusted, authenticated registry.
- If URL installation is necessary, enforce an allowlist of trusted HTTPS origins and reject redirects to origins outside that allowlist.
- Download the archive to a newly created, permission-restricted temporary directory instead of piping it directly into
tar. - Require a pinned SHA-256 or stronger digest and a verified publisher signature before extraction.
- Enumerate and validate every archive entry before extraction. Reject:
- Absolute paths.
- Paths containing
..components. - Device nodes and other special files.
- Symbolic or hard links that resolve outside the staging directory.
- Extract into an isolated staging directory using restrictive ownership and permissions.
- Review the manifest,
SKILL.md, scripts, binaries, links, and requested capabilities before activation. - Move reviewed content into the final Skill directory atomically and keep it disabled until explicit approval.
- Run Skills under least privilege with filesystem, command, credential, and network isolation.
- Record the source URL, final redirected URL, verified digest, signature identity, and installed files in an audit log.
