T03 · Remote Payload Retrieval and Execution
- Location
art_director.py:301- Finding
Unsafe Remote Installer Command Recommends Piping Downloaded Code Directly into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a coherent image-generation wrapper with some setup and dependency-safety caveats, but no evidence of hidden malicious behavior.
Before installing, understand that image briefs and your aesthetic file are used with a Gemini-backed generator, so do not include confidential or regulated content unless that is acceptable for your workflow. Only set NANO_BANANA_SCRIPT to a trusted local nano-banana-pro script, and prefer official package-manager or verified installation steps for uv instead of copying the printed curl-to-shell suggestion.
art_director.py:301Unsafe Remote Installer Command Recommends Piping Downloaded Code Directly into a Shell
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# Brand Aesthetic
<!--
This file defines your brand's visual identity. The Art Director skill reads
it on every image generation and merges it with the per-image brief written
by your calling agent.
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.
# Brand Aesthetic — Orbital
<!--
Bold flat vector graphics in the mid-century modernist poster tradition,
with a space-travel / scientific-diagram sensibility. Think Simon C. Page,
Brainstorm Design, NASA travel posters, Saul Bass, Massimo Vignelli.
The skill advertises shell, file read/write, and environment-variable use but does not declare any explicit tool scope or allowed-tools boundary. That increases the chance an agent runtime grants broader capabilities than necessary, enabling misuse of local files, shell execution, or secrets exposure if the skill is invoked in a permissive environment.
The skill instructs users to provide briefs and use a local aesthetic file, then forwards that content to an external image-generation service via Gemini/nano-banana-pro, but it does not clearly warn that user-provided content will leave the local environment. This can lead to unintentional disclosure of sensitive brand strategy, unpublished editorial plans, or proprietary creative direction to a third-party API.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
if matches:
return str(matches[0])
else:
result = subprocess.run(
["find", "/usr", str(Path.home() / ".openclaw"),
"-name", "generate_image.py", "-path", "*/nano-banana*"],
capture_output=True, text=True, timeout=5,
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
"--resolution", resolution,
]
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode != 0:
print("Generation failed:", file=sys.stderr)
This subprocess call launches a Python script path that can be sourced from the NANO_BANANA_SCRIPT environment variable through find_nano_banana(). Although subprocess.run is used safely without shell=True, an attacker who can control the environment or place a malicious script in a searched location can cause arbitrary code execution when batch generation runs.
"--filename", str(output_path),
"--resolution", resolution,
]
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode != 0:
print(f" [ERR] failed: {result.stderr.strip().splitlines()[-1] if result.stderr else 'unknown error'}")
There is a tainted flow from environment-controlled input to code execution: NANO_BANANA_SCRIPT is accepted as a candidate executable path and later passed to uv run. In an agent/skill context, environment variables are often externally influenced, so this creates a realistic arbitrary code execution path if an attacker can set env vars or shape the filesystem.
"--filename", str(output_path),
"--resolution", resolution,
]
result = subprocess.run(cmd, capture_output=True, text=True)
if result.returncode != 0:
print(f" [ERR] failed: {result.stderr.strip().splitlines()[-1] if result.stderr else 'unknown error'}")
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
if shutil.which("uv"):
print("[OK] uv is available")
else:
print("[ERR] uv not found -- install: curl -LsSf https://astral.sh/uv/install.sh | sh")
problems.append("uv")
aesthetic = load_aesthetic()
The anchor phrase "Like the diagrams in Japanese camera manuals" introduces a locale-specific stylistic constraint in the skill instructions. Under the policy, language or locale restrictions should be optional or clearly justified; here the locale reference is presented as a required aesthetic influence without any user choice or rationale.
No suspicious patterns detected.