T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:113- Finding
Unverified Remote Tool Download and Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is disclosed as an nginx tool explorer, but it also normalizes downloading, installing dependencies for, and executing remote tools without strong trust, verification, or approval controls.
Review this skill carefully before installing. Only use it with a trusted, HTTPS-protected nginx host, and do not let it execute downloaded tools or install dependencies unless a human verifies the source, checksum or signature, and runs the tool inside a disposable sandbox with no sensitive credentials.
SKILL.md:113Unverified Remote Tool Download and Execution
SKILL.md:173Remote Dependency Manifest Controls Package Installation
SKILL.md:12Plaintext HTTP Guidance and Disabled TLS Verification Default
SKILL.md:197Untrusted Remote README Content Drives Agent Decisions
The guide instructs users to run a destructive recursive delete command against a path under the home directory without any safety warning, path validation, or backup guidance. Although intended for legitimate uninstall, such commands are risky because copy/paste mistakes, variable expansion errors, or path edits can permanently delete local data.
# 移除技能目录
rm -rf ~/.openclaw/skills/nginx-explorer
# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer
The guide instructs users to run a destructive recursive delete command against a path under the home directory without any safety warning, path validation, or backup guidance. Although intended for legitimate uninstall, such commands are risky because copy/paste mistakes, variable expansion errors, or path edits can permanently delete local data.
# 移除技能目录
rm -rf ~/.openclaw/skills/nginx-explorer
# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer
This command recursively and forcibly deletes a workspace path and could cause unintended data loss if the placeholder path is replaced incorrectly or the command is run from copied documentation without careful editing. In a skill-installation guide, destructive filesystem operations are more dangerous because users may execute them verbatim during setup or removal workflows.
rm -rf ~/.openclaw/skills/nginx-explorer
# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer
# 从配置中移除
# 编辑 ~/.openclaw/openclaw.json,删除 nginx-explorer 条目
This command recursively and forcibly deletes a workspace path and could cause unintended data loss if the placeholder path is replaced incorrectly or the command is run from copied documentation without careful editing. In a skill-installation guide, destructive filesystem operations are more dangerous because users may execute them verbatim during setup or removal workflows.
rm -rf ~/.openclaw/skills/nginx-explorer
# 或从工作区移除
rm -rf /path/to/workspace/skills/nginx-explorer
# 从配置中移除
# 编辑 ~/.openclaw/openclaw.json,删除 nginx-explorer 条目
The skill is presented as an explorer for nginx-served directories, but its instructions extend into downloading and executing remote tools. That materially increases the trust boundary from passive discovery to arbitrary code execution from remotely hosted content, which could compromise the host or data if the server or content is malicious or tampered with.
The skill describes downloading and executing remote tools without a prominent, user-facing warning that this can alter the system and expose data. The absence of clear warnings increases the chance that users treat the workflow as routine exploration rather than a high-risk code-execution action.
These examples instruct users to fetch a script from the configured nginx server, mark it executable, and run it locally. A discovery-oriented skill should not normalize direct execution of remote code, because a malicious or compromised server can deliver arbitrary payloads that immediately execute with the agent's privileges.
These instructions write a downloaded file to disk, make it executable, and run it, but do not provide a prominent warning about persistence, privilege implications, or malicious payload risk. In practice, that omission lowers operator caution and can lead to unsafe execution of unreviewed remote code.
This workflow goes beyond exploration by downloading code and dependencies, then executing both installed packages and the fetched program. That creates a supply-chain and remote-code-execution path through untrusted nginx-hosted content, with added risk from dependency installation modifying the environment.
The workflow installs dependencies and runs a downloaded program without clearly warning that package installation can execute arbitrary setup logic and alter the environment. This creates both immediate code-execution risk and longer-term integrity risk from modifying the system with untrusted packages.
The markdown provides rm -rf commands for manual uninstallation, which are irreversible file deletions. In this section there is no adjacent warning or caution about permanent data removal or verifying the target path before execution.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 支持
- 查看技能文档:`cat ~/.openclaw/skills/nginx-explorer/SKILL.md`
- 访问 OpenClaw 文档:https://docs.openclaw.ai
- 加入社区:https://discord.com/invite/clawd
The README frames the skill as directory exploration, but its documented behavior explicitly includes downloading and executing remote tools. That creates a capability expansion from discovery to arbitrary code execution from an external server, which is a meaningful security risk if the nginx host, its contents, or transport are compromised.
The README presents downloading and executing external tools as a feature but does not give a strong user-facing warning that this is equivalent to running remote code of uncertain integrity. In this skill context, that omission is especially dangerous because the content is fetched from a configurable nginx server and may be treated as trusted by default.
The documentation normalizes executing downloaded tools as part of problem solving even though the skill's stated purpose is exploration/discovery. In context, this makes the agent more likely to escalate from browsing remote content to running untrusted code, increasing the chance of compromise, data exfiltration, or system abuse.
The trigger conditions are broad phrases like when conventional approaches fail or complex processing is required, which can cause the skill to activate in many situations without clear limits. Because this skill can lead to downloading and executing remote tools, ambiguous invocation criteria materially increase unsafe use.
The documented decision flow tells the agent to download and apply discovered tools to solve problems, which exceeds the declared purpose of exploration. Scope expansion like this is dangerous because users may invoke an apparently low-risk discovery skill without realizing it can escalate into executing arbitrary third-party tooling.
This troubleshooting step triggers an outbound network request to the configured NGINX endpoint. Although expected in context, the markdown does not explicitly disclose that the command contacts the remote server and may expose the configured URL in shell history or logs.
The README claims safeguards such as trusted servers, script review, and user confirmation, but the documented quick-start and workflow present direct execution without any enforced controls. This mismatch can create a false sense of safety and lead operators or agents to run external tools without the promised validation steps.
Detected: suspicious.destructive_delete_command