T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:108- Finding
Unverified Remote Installation Script Executed Directly by Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Tesla/OpenClaw setup guide, but it asks users to install mutable external components and handle vehicle/gateway credentials without enough safety guidance.
Review carefully before installing. Prefer package-manager or signed-install methods over curl|sh, pin reviewed versions where possible, use a virtual environment for Python, avoid putting secrets on command lines, restrict permissions on ~/.config/tescmd files, and be prepared to rotate Tesla/OpenClaw credentials if they are exposed.
SKILL.md:108Unverified Remote Installation Script Executed Directly by Shell
SKILL.md:124Security-Critical Third-Party Packages Installed Without Version or Integrity Pinning
SKILL.md:224Gateway and OAuth Secrets May Be Exposed Through Process Arguments and Plaintext Configuration
The guide recommends piping a remotely fetched script directly into sh, which removes the user's opportunity to inspect what will run and executes network-delivered code immediately. If the download source, DNS, TLS termination, or upstream distribution is compromised, this becomes instant arbitrary code execution on the host, especially dangerous in a setup flow that later handles Tesla and Gateway credentials.
If not installed:
brew install tailscale or download from https://tailscale.com/downloadcurl -fsSL https://tailscale.com/install.sh | shIf not logged in:
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
If missing, install it:
- macOS: `xcode-select --install`
- Linux: `sudo apt install git` or `sudo dnf install git`
#### Required: GitHub CLI (gh)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
If missing, install it:
- macOS: `xcode-select --install`
- Linux: `sudo apt install git` or `sudo dnf install git`
#### Required: GitHub CLI (gh)
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
If not logged in:
sudo tailscale up
Tell the user: "Please complete the Tailscale login in your browser if prompted."
The setup text states that the Gateway-issued authentication token is saved to ~/.config/tescmd/bridge.json, but it does not warn the user that this is a persistent credential that can be reused by anyone with local file access. In a vehicle-control integration, theft of that token could let an attacker reconnect a rogue node to the Gateway and access telemetry or command paths until the token is revoked.
The skill provides example environment variables for TESLA_CLIENT_SECRET and OPENCLAW_GATEWAY_TOKEN without any handling guidance, which normalizes placing long-lived secrets in a plaintext .env file. Those credentials can be exposed through shell history, backups, support bundles, source-control accidents, or weak permissions, and in this context they may enable vehicle API access and Gateway authentication.
No suspicious patterns detected.