T03 · Remote Payload Retrieval and Execution
- Location
scripts/run_video_query.sh:61- Finding
Unverified Remote Runtime Retrieval and Execution with API Credentials
- Content
View full analysis
/dev/null 2>&1 || { log_error "Failed to clone ${PINNED_REPO_URL} at tag ${PINNED_TAG}." log_error "Check network access and that the release tag exists." exit 2 } else ( cd "${MANAGED_RELEASE_DIR}" git fetch --depth 1 origin "refs/tags/${PINNED_TAG}:refs/tags/${PINNED_TAG}" >/dev/null 2>&1 || true git checkout --detach "${PINNED_TAG}" >/dev/null 2>&1 || { log_error "Failed to checkout pinned runtime tag ${PINNED_TAG}." exit 2 } ) fi ( cd "${MANAGED_RELEASE_DIR}" uv sync --frozen --no-dev >/dev/null 2>&1 || { log_error "Failed to install runtime dependencies with uv sync." exit 2 } ) } ``` ```bash main() { require_binary uv require_env_key GOOGLE_API_KEY require_env_key YOUTUBE_API_KEY RUNTIME_ROOT="$(resolve_runtime_root)" cd "${RUNTIME_ROOT}" uv run python -m video_sourcing_agent.integrations.openclaw_runner "$@" } ``` The associated Skill instruction explicitly requires unsandboxed execution: ```markdown This workflow expects host runtime execution (sandbox mode off). The runner auto-bootstraps a pinned runtime from `Memori ...[truncated 3729 chars]- Remediation
View remediation
