T03 · Remote Payload Retrieval and Execution
- Location
skills/grok-twitter-search/scripts/setup_interactive.py:35- Finding
Remote Installer Is Downloaded and Piped Directly to a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This package looks like a personal OpenClaw workspace bundled with several unrelated high-privilege skills, so it needs review before installation.
Install only in an isolated OpenClaw profile after removing unrelated workspace memory/persona files, pinning install versions, avoiding curl-to-shell setup, and using dedicated low-value API keys and a low-value blockchain wallet. Do not use the Four.Meme trading skill with a primary wallet, and review any heartbeat or memory automation before enabling it.
skills/grok-twitter-search/scripts/setup_interactive.py:35Remote Installer Is Downloaded and Piped Directly to a Shell
skills/grok-twitter-search/scripts/setup_interactive.py:245Setup Wizard Prints and Stores the Complete Grok API Key in Plaintext
skills/grok-twitter-search/scripts/search_twitter.py:24Custom API Base Can Redirect the Grok Bearer Credential to an Arbitrary Server
skills/four-meme-ai/SKILL.md:90Unpinned Global Package Is Executed with Access to a Wallet Private Key
opennews-mcp/src/opennews_mcp/api_client.py:106OpenNews WebSocket Authentication Token Is Embedded in the URL Query String
protobufjs 6.11.4 is a known vulnerable version with multiple advisories including denial of service, recursion-based exhaustion, and possible code-injection issues in generated code paths. Because this package is used transitively by onnx-proto/onnxruntime-web, any workflow that ingests untrusted model or protobuf-derived content could expose the skill to crashes or worse, depending on how code generation features are used.
Skill modifies its own code, configuration, or behavior at runtime. Self-modification enables an agent to escalate privileges, disable safety constraints, or install persistent backdoors.
## Why Separate?
Skills are shared. Your setup is yours. Keeping them apart means you can update skills without losing your notes, and share skills without leaking your infrastructure.
---
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.
~/.continue/config.yaml:
mcpServers:
sharp 0.32.6 is flagged for inherited vulnerabilities in native image-processing libraries such as libvips/libheif. If this skill processes attacker-controlled images, those native parsing bugs can lead to denial of service and potentially memory-safety exploitation in the underlying libraries.
The skill instructs users to place PRIVATE_KEY in a .env file in the current working directory. Storing a raw blockchain private key in project-local plaintext materially increases the risk of accidental commit, leakage via tooling, exposure to other local processes, or theft by malicious dependencies reading the working directory.
**When not using OpenClaw (standalone)**
Set **PRIVATE_KEY** and optionally **BSC_RPC_URL** via the process environment so they are available when running `npx fourmeme` or `node bin/fourmeme.cjs`:
- **.env file**: Put a `.env` file in **the directory where you run the `fourmeme` command** (i.e. your project / working directory). Example: if you run `fourmeme quote-buy ...` from `/path/to/my-project`, place `.env` at `/path/to/my-project/.env`. The CLI automatically loads `.env` from that current working directory. Use lines like `PRIVATE_KEY=...` and `BSC_RPC_URL=...`. Do not commit `.env`; add it to `.gitignore`.
- **Shell export**: `export PRIVATE_KEY=your_hex_key` and `export BSC_RPC_URL=https://bsc-dataseed.binance.org` (or another BSC RPC), then run `npx fourmeme <command> ...`.
### Declared and optional environment variables
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
]
if proxy and proxy != "auto":
env = os.environ.copy()
env["SOCKS5_PROXY"] = proxy
else:
env = os.environ.copy()
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
]
if proxy and proxy != "auto":
env = os.environ.copy()
env["SOCKS5_PROXY"] = proxy
else:
env = os.environ.copy()
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
print("\n💡 WARP 安装指南:")
print(" Ubuntu/Debian:")
print(" curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp.asc | \\")
print(" sudo gpg --dearmor -o /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg")
print(" echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
print(" https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
print(" sudo tee /etc/apt/sources.list.d/cloudflare-client.list")
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
print("\n💡 WARP 安装指南:")
print(" Ubuntu/Debian:")
print(" curl -fsSL https://pkg.cloudflareclient.com/cloudflare-warp.asc | \\")
print(" sudo gpg --dearmor -o /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg")
print(" echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
print(" https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
print(" sudo tee /etc/apt/sources.list.d/cloudflare-client.list")
Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.
print(" echo 'deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] \\")
print(" https://pkg.cloudflareclient.com/ $(lsb_release -cs) main' | \\")
print(" sudo tee /etc/apt/sources.list.d/cloudflare-client.list")
print(" sudo apt update && sudo apt install cloudflare-warp")
print(" sudo systemctl start warp-svc")
print(" warp-cli registration new && warp-cli connect")
The file explicitly says MEMORY.md must only be loaded in main sessions because it may contain personal context, but later heartbeat instructions tell the agent to review and update MEMORY.md without restating or enforcing that boundary. In any shared or loosely scoped heartbeat context, this can cause unauthorized reading, summarization, or propagation of sensitive long-term memory.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
## Safety
- Don't exfiltrate private data. Ever.
- Don't run destructive commands without asking.
- `trash` > `rm` (recoverable beats gone forever)
- When in doubt, ask.
These lines switch to Chinese for an operationally important notice, but the file does not offer a language choice or explain a required locale. This can violate language policy expectations by implicitly forcing a specific language without user opt-in.
The heartbeat trigger guidance is broad and can activate on a configurable prompt with limited scoping, encouraging the agent to take action whenever a message loosely matches the pattern. That increases the chance of prompt-triggered behavior in unintended contexts, including background checks or outbound notifications not actually authorized by the current user interaction.
The file authorizes proactive actions 'without asking,' including reading and organizing memory files, checking projects, and updating documentation. Even if framed as helpful automation, this grants unsupervised access to sensitive local context and can cause unintended data exposure, persistence changes, or repository modifications.
- Nothing new since last check
- You just checked <30 minutes ago
**Proactive work you can do without asking:**
- Read and organize memory files
- Check on projects (git status, etc.)
The file defines a fixed Chinese-language persona ('瓜助理', '技术瓜的 AI 小助理') and communication style without indicating that this should adapt to user preference. This can inappropriately constrain agent behavior, causing unwanted language or persona steering that may reduce usability, mislead users about the assistant's identity, or conflict with deployment requirements.
The document includes a destructive find ... -delete command that removes files older than 30 days without any warning, confirmation step, backup guidance, or scope validation. In an agent/skill context, operators may copy-paste or automate this directly, increasing the risk of unintended data loss if the path is wrong, retention assumptions are incorrect, or memory files are still needed.
Skill enumerates or reads other installed skills. Access to other skills' SKILL.md files or the skills directory reveals prompt instructions, capabilities, and secrets that should be invisible to peer skills.
## 📚 文档
- **README**: `/Users/ben/.openclaw/workspace/qmd/README.md`
- **Skill 文档**: `/Users/ben/.openclaw/workspace/skills/qmd-memory/SKILL.md`
---