T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:26- Finding
Unpinned Remote Skill Retrieval and Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26–32
Vulnerability Type: Unpinned retrieval and installation of mutable remote skill content
Risk Level: Mediummarkdown The canonical, up-to-date version lives at: 👉 **https://clawhub.ai/c4pt0r/mem9-ai** ## How to update Replace this file with the latest version: ```bash # Install from ClawHub directly: openclaw skills install c4pt0r/mem9-aiTechnical Analysis
The deprecated local skill instructs users to install the latest version of an externally maintained skill. The command does not specify an immutable version, cryptographic digest, or signature requirement, and it provides no review or verification step before installation.
Consequently, the effective skill installed by this instruction can change after the audited local file has been reviewed. Although the current repository contains no embedded malicious scripts, credential access, persistence, or exfiltration logic, its update process transfers trust to mutable remote content outside the audit boundary.
This is best classified as remote payload retrieval because the instruction causes externally controlled skill content to be fetched and installed. Exploitation would require the remote package, publisher account, distribution service, or delivery path to become malicious or compromised.
Attack Path
- A user or agent loads the deprecated local skill and follows its update instructions.
- The user runs
openclaw skills install c4pt0r/mem9-ai. - OpenClaw retrieves the package version currently published under that remote identifier.
- Because no version or digest is pinned, the retrieved content may differ from content previously reviewed.
- If the publisher account or supply chain is compromised, attacker-controlled instructions or executable components can be installed.
- When the installed skill is subsequently loaded or invoked, that content can operate ...[truncated 707 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable package reference with a pinned, audited version or immutable content digest.
- Require cryptographic signature verification and validate the expected publisher identity before installation.
- Download the package into a staging area and present its files, scripts, permissions, and external dependencies for review before activation.
- Prevent automatic execution of post-install scripts unless they have been explicitly reviewed and approved.
- Document the exact tools, filesystem paths, network destinations, and credentials required by the replacement skill.
- Run the installed skill with least privilege, restricting filesystem, network, command-execution, and secret access to what is strictly necessary.
- Retain a known-good package or lockfile so installations can be reproduced and rolled back safely.
