T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:48- Finding
Unpinned Remote Repository Is Retrieved and Its Code Is Executed Locally
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 48–60
Vulnerability Type: Unpinned executable third-party dependency
Risk Level: MediumVulnerable Code
markdown 1. Clone the repository: - `git clone https://github.com/MilleniumGenAI/deep-research-openclaw-agent.git`Followed by:
bash python -m py_compile openclaw/workspace-researcher/scripts/*.py python openclaw/workspace-researcher/scripts/init_research_run.py --workspace openclaw/workspace-researcher --topic "Smoke test" --language en --task-date 2026-03-10Technical Analysis
The installation procedure clones the repository's mutable default branch without pinning a reviewed commit or release and without verifying a cryptographic checksum or signature. It subsequently directs the user to execute a Python script obtained from that repository.
Because the effective executable content can change after this skill is reviewed, the local
SKILL.mdaudit cannot establish the safety of the code that users will eventually run. Thepy_compilecommand only validates Python syntax; it does not establish integrity or prevent malicious behavior wheninit_research_run.pyis executed.This is primarily a supply-chain weakness. It also creates a remote payload retrieval and execution channel because upstream changes directly determine the code executed by users.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, or its default branch.
- The attacker modifies
init_research_run.py, another imported Python module, or copied OpenClaw prompt/configuration content. - A user follows
SKILL.mdand clones the current default branch. - No commit pin, checksum, or signature check detects that the reviewed content has changed.
- The user executes the downloaded initialization script as instructed.
- The malicious code runs with the permissions and environmental access of that user.
...[truncated 718 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation to a specific, reviewed commit hash rather than cloning the mutable default branch.
- Publish expected SHA-256 hashes for all executable scripts and verify them before execution.
- Prefer signed release artifacts or signed commits/tags and document signature verification.
- Vendor the reviewed scripts into the skill package when practical, making the audited package the runtime source of truth.
- Review the entire Python import chain and all copied prompt/configuration files, not only the directly invoked script.
- Run initialization in a sandbox with minimal filesystem access, no unnecessary network access, and only the environment variables required for the smoke test.
- Do not expose
TAVILY_API_KEYduring local-only validation; inject it only when Tavily-backed research is explicitly requested. - Replace syntax compilation as a security check with integrity verification and dependency/security scanning. Retain
py_compileonly as a separate correctness check.
