T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Mutable Remote Skill Files Installed Without Integrity Verification
- Content
View full analysis
~/.openclaw/skills/clawdr/SKILL.md curl -s https://clawdr-eta.vercel.app/heartbeat.md > ~/.openclaw/skills/clawdr/HEARTBEAT.md curl -s https://clawdr-eta.vercel.app/skill.json > ~/.openclaw/skills/clawdr/package.json ``` ### Technical Analysis The installation procedure downloads mutable Skill instructions, heartbeat instructions, and metadata directly from a remote deployment. It does not pin a version, validate a cryptographic checksum, verify a digital signature, or require review of the downloaded content. The use of HTTPS protects traffic against ordinary network interception, and the files are not directly piped into a shell. Nevertheless, the effective Skill content can change after this audited artifact has been reviewed. Compromise of the service, hosting account, deployment pipeline, or domain could cause users to install instructions that differ from the reviewed version. The `HEARTBEAT.md` file is particularly relevant because heartbeat instructions may cause recurring Agent activity. Although no malicious remote payload is present in the audited file, the installation mechanism creates a supply-chain trust boundary without integrity controls. ### Attack Path 1. An attacker compromises the Clawdr deployment, hosting account, publishing pipeline, or associated domain. 2. The attacker replaces `skill.md`, `heartbeat.md`, or `skill.json` with altered content. 3. A user follows the documented installation commands. 4. `curl` writes the attacker-controlled files into the local OpenClaw Skill directory without checking their identity or integrity. 5. OpenClaw subsequently loads the modified instructions or heartbeat behavior. 6. The altered Skill could attemp ...[truncated 933 chars]- Remediation
View remediation
