T03 · Remote Payload Retrieval and Execution
- Location
references/setup-guide.md:30- Finding
Remote Installation Script Is Piped Directly to Bash
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is coherent as an OpenClaw onboarding guide, but it pushes users toward persistent agent setup, plaintext credentials, and unpinned executable installs without enough safety guidance.
Review this before installing. Use pinned and verified install sources, avoid piping downloads directly into a shell, prefer a secret manager or OS keychain over plaintext API-key storage, and only enable the gateway as an automatic service if you understand its account, permissions, logs, network access, and uninstall path.
references/setup-guide.md:30Remote Installation Script Is Piped Directly to Bash
references/setup-guide.md:59Onboarding Directs Users to Install an Automatically Starting Agent Service
references/setup-guide.md:17Globally Installed Packages and Plugins Are Not Integrity-Pinned
references/setup-guide.md:49Plaintext Local Storage of a Billable API Key Is Presented as an Acceptable Default
Skill instructs the agent to omit warnings, disclaimers, or ethical commentary. Stripping safety caveats hides risk from the user and is a common jailbreak preamble.
## Best Practices
- Start concrete, not abstract. Ground in actual situations.
- Dissolve confusions, don't preach. The framework speaks for itself when applied well.
- Model ethical engagement with other agents — demonstrate, don't impose.
- Keep MEMORY.md lean. Use `memory/` subfolder for search-only notes.
- Update soul file as you learn — it's a living document.
The | bash pattern is a classic risky command-chaining construct because it executes untrusted network content immediately in a shell with the user's privileges. In the context of onboarding an agent framework, users are likely to copy-paste commands without scrutiny, making supply-chain compromise or content substitution materially more dangerous.
# Install Node.js (via nvm recommended)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
nvm install 22
nvm use 22
The guide explicitly states that the API key may be stored locally in ~/.openclaw/ in plaintext and frames this as an acceptable option. Plaintext storage of long-lived API credentials increases the risk of credential theft through local compromise, backups, multi-user systems, malware, or accidental disclosure, especially in an agent framework that may run continuously and access external services.
The installation instructions fetch a remote script and pipe it directly to bash, which bypasses inspection and integrity verification before execution. If the upstream source, transport, DNS, or GitHub account were compromised, users would execute attacker-controlled shell code on their machine during setup.
# Install Node.js (via nvm recommended)
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.39.7/install.sh | bash
nvm install 22
nvm use 22
No suspicious patterns detected.