T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:42- Finding
Unpinned Remote Repository Is Retrieved and Executed During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42-51
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highmarkdown ## Install 1. Clone the repository: - `git clone https://github.com/MilleniumGenAI/coder-openclaw-agent.git` 2. Copy `openclaw/workspace-coder/` into your OpenClaw base directory, or point your agent config at that path directly. 3. Build the sandbox image from the repository root: - `docker build -f docker/coder-sandbox.dockerfile -t coder-sandbox:latest .` 4. Register the agent in `openclaw.json` using: - `openclaw/agent-config.template.json` 5. If your main agent delegates coding tasks, align it with: - `openclaw/main-coder-prompt.md`Technical Analysis
The installation procedure clones the default branch of an external GitHub repository without selecting a reviewed commit, immutable release, or cryptographically verified artifact. It then builds a Docker image from the retrieved content and incorporates remote prompt and configuration files into OpenClaw.
Because the repository reference is mutable, the effective code and agent instructions executed by users can change after this skill has been reviewed. A compromised maintainer account, malicious upstream update, or repository takeover could alter the Dockerfile, build context, agent configuration, or prompt files. Docker build instructions can execute commands during image construction, while imported configuration and prompt content can subsequently influence agent behavior.
The mutable
coder-sandbox:latesttag also provides no reliable association between the installed image and a specific audited source revision.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or the repository's default branch.
- The attacker modifies the Dockerfile or files included in the Docker build context. Alternatively, the attacker changes the agent con ...[truncated 1558 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the repository to a specific, reviewed full commit hash rather than cloning and using the default branch:
bash git clone https://github.com/MilleniumGenAI/coder-openclaw-agent.git cd coder-openclaw-agent git checkout --detach <reviewed-full-commit-hash> - Prefer signed, immutable releases and verify the maintainer's Git signature or release provenance before installation.
- Publish expected SHA-256 checksums for the Dockerfile, build context, agent configuration, and prompt files. Abort installation if verification fails.
- Replace the mutable
coder-sandbox:latesttag with a version and source-revision-specific tag. Where images are distributed, reference them by immutable image digest. - Review the Dockerfile and every file copied into the build context before running
docker build. Use an explicit minimal build context and.dockerignorefile. - Build with an isolated, rootless builder where possible. Do not expose host sockets, credentials, SSH agents, secrets, privileged mode, or unrestricted host mounts to the build.
- Review
agent-config.template.json,main-coder-prompt.md, and the workspace prompt pack before registering them. Enforce least-privilege tool and filesystem permissions independently of prompt instructions. - Document the exact approved revision in
SKILL.mdand establish an explicit review process before updating it.
- Pin the repository to a specific, reviewed full commit hash rather than cloning and using the default branch:
