T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:98- Finding
Unverified Mutable Remote Binary Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 98–101
Vulnerability Type: Remote executable retrieved from a mutable URL without integrity verification
Risk Level: HighVulnerable Code:
bash # Linux x86_64 curl -L https://github.com/Perseus-Computing-LLC/mimir/releases/latest/download/mimir-linux-x86_64 -o mimir chmod +x mimir sudo mv mimir /usr/local/bin/Technical Analysis
The installation procedure retrieves an executable from a mutable
latestrelease URL, marks it executable, and installs it into the system-wide/usr/local/bindirectory. It does not pin an audited release version or verify a cryptographic checksum or signature.Consequently, the effective executable can change after the Skill has been reviewed. Compromise of the upstream repository, release account, release artifact, or download path could cause users to install an attacker-controlled binary. Although the command does not execute the binary immediately, later setup instructions and MCP configuration cause it to run as the invoking user.
The use of
sudoto place the executable in a system-wide location also exceeds the minimum privileges needed for the declared functionality. Mimir could instead be installed and executed from a user-owned directory.Attack Path
- An attacker compromises the upstream release process, maintainer account, or downloadable
latestartifact. - The attacker replaces the binary with a malicious executable.
- A user follows the documented installation procedure and downloads the altered artifact without integrity verification.
- The user marks the artifact executable and installs it into
/usr/local/bin. - OpenClaw or the user subsequently invokes
mimiras an MCP server. - The malicious binary executes with the permissions of the OpenClaw process or invoking user, gaining access to files, environment variables, agent memories, and reachable local services availab ...[truncated 732 chars]
- An attacker compromises the upstream release process, maintainer account, or downloadable
- Remediation
View remediation
Remediation Suggestions
- Pin a specific audited release version instead of using the mutable
latestURL. - Publish an expected SHA-256 or stronger digest through a separately protected channel and verify it before setting executable permissions.
- Prefer cryptographically signed releases and validate the signature against a documented maintainer key.
- Abort installation if checksum or signature verification fails.
- Install the executable in a user-owned directory such as
~/.local/bininstead of usingsudoand/usr/local/bin. - Document the exact reviewed version and provide an explicit upgrade procedure that repeats integrity verification.
- For source builds, pin a release tag or commit and verify the signed tag or commit before building.
- Pin a specific audited release version instead of using the mutable
