T03 · Remote Payload Retrieval and Execution
- Location
scripts/install-vennporter.sh:17- Finding
Mutable Remote Source and Unverified Dependencies Are Downloaded and Executed
- Content
View full analysis
/dev/null 2>&1; then pnpm install pnpm build else npm install npm run build fi ``` The installer is invoked by the automated setup configuration in `SKILL.md`, lines 25-27: ```yaml on_ready: - command: "bash ~/.openclaw/workspace/skills/venn/scripts/install-vennporter.sh" help: "Install/build vennporter (device_code-capable fork)" ``` ### Technical Analysis The installer clones the mutable `feat/device-code-grant` branch from a third-party GitHub repository rather than checking out a reviewed, immutable commit. On subsequent executions, `git pull --ff-only` retrieves the latest branch contents without signature, commit allowlist, or checksum verification. After retrieval, the script executes `pnpm install` or `npm install` and then runs the project's build command. Package installation can execute dependency lifecycle scripts, while the build command executes scripts defined by the remotely retrieved project. Consequently, the effective code executed on the host can change after this skill package has been audited. The script also does not enforce a verified dependency lockfile or an installation mode such as `npm ci`. The security of the resulting executable therefore depends on the continued integrity of the remote repository, its maintainer account, the package registry, and the complete transitive dependency graph. ### Attack Path 1. An attacker compromises the upstream repository, its maintainer account, the mutable branch, or a dependency selected during installation. 2. The att ...[truncated 1416 chars]- Remediation
View remediation
