T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Remote Installer Executed Directly by Bash
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 30
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: HighVulnerable Code:
bash curl -fsSL https://openclaw.ai/install.sh | bashTechnical Analysis
The installation instructions stream a remotely hosted shell script directly into Bash. The downloaded payload is not pinned to a version, saved for inspection, checked against a cryptographic digest, or verified using a trusted signature.
HTTPS protects the connection in transit but does not make the installer immutable. The effective code can change after this Skill has been reviewed. Compromise of the domain, hosting infrastructure, CDN, release process, or installer itself would allow arbitrary commands to be returned and executed with the privileges of the user running the command.
This behavior exceeds the minimum privileges necessary for an instructional setup Skill. The Skill can provide installation guidance without causing mutable external content to be executed immediately and without verification.
Attack Path
- An attacker compromises the installer host, its deployment process, or another component serving
https://openclaw.ai/install.sh. - The attacker replaces or modifies the installer with malicious shell commands.
- A user or agent follows the documented setup procedure.
curlretrieves the attacker-controlled content.- The shell pipeline passes that content directly to Bash without an inspection or integrity-verification step.
- Bash executes the payload using the current user's privileges.
- The payload can modify user-accessible files, access data and credentials available to that account, install additional components, or prepare persistent execution.
Impact Assessment
Successful exploitation provides arbitrary command execution with the privileges of the invoking user. This can expose files, environment variables ...[truncated 586 chars]
- An attacker compromises the installer host, its deployment process, or another component serving
- Remediation
View remediation
Remediation Suggestions
- Do not pipe network content directly into a shell.
- Download a version-pinned release artifact as a separate operation.
- Publish and verify a cryptographic signature from a trusted release key. A pinned SHA-256 digest may be used as an additional integrity check.
- Stop installation if signature or digest verification fails.
- Permit the user to inspect the downloaded installer before execution.
- Execute the verified artifact in a separate, explicit command only after informed user approval.
- Avoid elevated privileges unless a documented installation step specifically requires them.
- Prefer a trusted package manager or signed release package with reproducible provenance.
- Document the expected files, network endpoints, and system changes made by the installer.
A safer conceptual workflow is:
bash curl -fSLo openclaw-install.sh "https://openclaw.ai/releases/PINNED_VERSION/install.sh" sha256sum -c openclaw-install.sh.sha256 # Inspect the downloaded file and verify its publisher signature. bash openclaw-install.sh
