T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Release Binary Is Downloaded and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:30-35
Vulnerability Type: Remote payload retrieval without checksum or signature verification
Risk Level: MediumVulnerable Code:
bash TAG=$(curl -fsSL "https://api.github.com/repos/PanthroCorp-Limited/openclaw-skills/releases" \ | grep -o '"tag_name":"google-workspace/v[^"]*"' | head -1 | cut -d'"' -f4) VERSION=${TAG#google-workspace/v} curl -fsSL "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/${TAG}/google-workspace_${VERSION}_linux_arm64.tar.gz" \ | tar -xz -C ~/.openclaw/bin/ google-workspace chmod +x ~/.openclaw/bin/google-workspaceTechnical Analysis
The installation procedure dynamically selects the latest GitHub release and streams its archive directly into
tar. The installed file is then marked executable without validating a pinned cryptographic digest or trusted signature.HTTPS protects the download in transit but does not protect against compromise of the publisher's GitHub account, release workflow, repository, or release artifacts. Because the selected tag is not pinned, the effective executable can change after the Skill has been reviewed.
The repository includes SHA-256 checksums in
dist/checksums.txt, including a checksum for the Linux ARM64 archive, but the documented installation flow does not use them. This behavior is security-sensitive because the resulting executable runs in an environment containingGOOGLE_CLIENT_ID,GOOGLE_CLIENT_SECRET, andGOOGLE_WORKSPACE_TOKEN_KEY. It can also read and decrypt the stored OAuth token when invoked with those environment variables.Attack Path
- An attacker compromises the GitHub release account, repository workflow, or artifact publication process.
- The attacker publishes or replaces the release archive selected by the dynamic tag lookup.
- An operator follows the installation instructions.
curldownloads the modified arch ...[truncated 1189 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin installation instructions to a specific reviewed version rather than dynamically selecting the latest release.
- Download the archive and checksum manifest to temporary files instead of streaming the archive directly into
tar. - Verify the archive using a pinned SHA-256 digest before extraction:
bash VERSION="0.5.2" ARCHIVE="google-workspace_${VERSION}_linux_arm64.tar.gz" curl -fL -o "$ARCHIVE" \ "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/google-workspace/v${VERSION}/${ARCHIVE}" echo "c1d430a17457f9ce0d1f9c38eac5d816652ac9bd1150a4ee4c21c2b642e245ac ${ARCHIVE}" \ | sha256sum -c - tar -xzf "$ARCHIVE" -C ~/.openclaw/bin/ google-workspace chmod 0755 ~/.openclaw/bin/google-workspace - Prefer cryptographically signed releases, such as Sigstore/Cosign attestations, and verify the expected publisher identity and build provenance.
- Extract to a temporary directory, validate the expected file type and name, and move the verified binary atomically into place.
- Run the binary under a dedicated least-privilege account and expose credentials only for commands that require them.
