T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:30- Finding
Unverified Remote Executable Download and Installation
- Content
View full analysis
- Remediation
View remediation
" curl -fL --proto '=https' \ "https://github.com/PanthroCorp-Limited/openclaw-skills/releases/download/zoho-mail/v${VERSION}/${ARCHIVE}" \ -o "/tmp/${ARCHIVE}" printf '%s %s\n' "${EXPECTED_SHA256}" "/tmp/${ARCHIVE}" | sha256sum --check - tar -xzf "/tmp/${ARCHIVE}" -C ~/.openclaw/bin/ zoho-mail chmod 0755 ~/.openclaw/bin/zoho-mail rm -f "/tmp/${ARCHIVE}" ``` 5. Prefer signed release artifacts and verify the signature against a public key distributed independently of the release repository. 6. Where available, verify build provenance or use reproducible builds so the installed executable can be matched to the audited source. 7. Extract into a staging directory and atomically install only after all validation succeeds. ]]>
