T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:25- Finding
Unverified Remote Executable Retrieved from Maintainer-Controlled Releases
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This AWS CLI skill is purpose-aligned, but it installs an unverified executable that can automatically use AWS credentials, so users should review it before installing.
Install only if you trust the publisher and the release channel. Prefer a pinned version with published checksums or signatures, run it under a least-privileged AWS identity, and be aware that EC2/ECS metadata credentials may be used automatically inside the container.
SKILL.md:25Unverified Remote Executable Retrieved from Maintainer-Controlled Releases
scripts/package.sh:37Upstream AWS Installer Executed Without Cryptographic Verification
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
AWS_VER_DIR="${versions[0]}"
if [[ -L "${STAGING}/aws-cli/v2/current" ]]; then
rm -f "${STAGING}/aws-cli/v2/current"
ln -s "${AWS_VER_DIR}" "${STAGING}/aws-cli/v2/current"
fi
if [[ -L "${STAGING}/bin/aws" ]]; then
Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).
ln -s "${AWS_VER_DIR}" "${STAGING}/aws-cli/v2/current"
fi
if [[ -L "${STAGING}/bin/aws" ]]; then
rm -f "${STAGING}/bin/aws" "${STAGING}/bin/aws_completer"
ln -s ../aws-cli/v2/current/bin/aws "${STAGING}/bin/aws"
ln -s ../aws-cli/v2/current/bin/aws_completer "${STAGING}/bin/aws_completer"
fi
The documentation states that the packaging script downloads and runs the AWS CLI installer, which is execution of a third-party binary obtained over the network. Even if this is the expected build mechanism for this skill, the absence of explicit integrity verification, provenance details, or a warning about the trust boundary creates a real supply-chain risk: a compromised download source, tampered artifact, or unsafe mirror could lead to arbitrary code execution during packaging.
The skill clearly exposes shell-capable installation and usage flows but does not declare any tool scope or permissions boundary. In an agent ecosystem, missing scope metadata can cause the skill to be invoked without clear operator awareness of its ability to execute commands, perform network access, and interact with cloud resources.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Download the release tarball for your architecture and extract:
TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \
| grep -o '"tag_name":"aws-cli/v[^"]*"' | head -1 | cut -d'"' -f4)
VERSION=${TAG#aws-cli/v}
ARCH=$(uname -m); [ "$ARCH" = "aarch64" ] && ARCH="arm64" || ARCH="amd64"
Data is uploaded to cloud storage (S3 / GCS / Azure Blob). This may be a legitimate backup or exfiltration to an external bucket. Manual review is recommended.
aws s3 ls s3://my-bucket/
aws s3api list-objects-v2 --bucket my-bucket --prefix parsed/
aws s3 cp s3://my-bucket/key.json /tmp/key.json
aws sts get-caller-identity
The authentication section states that credentials resolve automatically via the default provider chain and specifically highlights IMDS use in EC2/ECS, but it does not warn that invoking the CLI may silently reach the instance metadata service and acquire cloud credentials. In containerized or multi-tenant environments, this can unexpectedly expose role credentials and enable broader AWS access than the operator intended.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
trap cleanup EXIT
echo "Downloading AWS CLI v2 for linux/${ARCH}..."
curl -fsSL "https://awscli.amazonaws.com/awscli-exe-linux-${AWS_ARCH}.zip" -o "${WORK_DIR}/awscli.zip"
ZIP_SIZE=$(stat --format=%s "${WORK_DIR}/awscli.zip")
MIN_ZIP_SIZE=$((30 * 1024 * 1024))
The installation instructions fetch release metadata and a tarball over the network, then immediately extract and symlink binaries into the user's tool path without any integrity verification or safety warning. This creates a supply-chain and local system modification risk if the release source, network path, or selected artifact is compromised.
No suspicious patterns detected.