T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:23- Finding
Unverified Remote Installer Scripts Are Executed Directly
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 23 and lines 85–87
Vulnerability Type: Remote payload retrieval and immediate execution
Risk Level: CriticalVulnerable Code
At line 23:
sh curl -fsSL clawheart.live/install.sh | shAt lines 85–87:
sh curl -fsSL https://clawheart.live/install.sh | sh iwr https://clawheart.live/install.ps1 -useb | iexTechnical Analysis
The Skill instructs users or an AI Agent to download mutable scripts from an external server and pass the responses directly to a command interpreter. The Unix instructions pipe the response to
sh, while the Windows instruction sends the response to PowerShell'sInvoke-Expressionalias,iex.No version pinning, cryptographic signature verification, checksum validation, content review, or trusted package-manager verification occurs before execution. Consequently, the effective code is controlled by the remote endpoint at installation time and can change after the Skill package has been reviewed.
The command on line 23 additionally omits an explicit
https://scheme. Depending on client behavior and server redirects, this can create an avoidable risk of plaintext transport or unsafe redirection before reaching HTTPS.Installing the CLI may support the Skill's declared functionality, but direct remote execution is not the minimum-risk installation method. A downloaded, versioned, and cryptographically verified artifact would provide the same functionality without automatically treating a network response as executable code. The repository does not include the installer source, so its behavior, requested permissions, and safety cannot be audited here.
Attack Path
- A user asks the Agent to perform a ClawHeart security operation.
- The Agent determines that the
clawheartexecutable is not available. - Following
SKILL.md, the Agent recommends or facilitates one of the remote installation com ...[truncated 1225 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove all direct download-and-execute patterns, including
curl | shandiwr | iex. - Use explicit HTTPS URLs in every installation instruction.
- Publish immutable, versioned release artifacts through a documented release channel.
- Sign release artifacts and document verification using a trusted public key or platform-native code-signing mechanism.
- Publish SHA-256 or stronger checksums through an independently protected channel and require verification before execution.
- Split downloading and execution into separate steps so users can inspect the artifact before running it.
- Prefer reputable package managers with a pinned package and version where possible.
- Document the installer's expected filesystem changes, network access, and required permissions. Ensure it does not require administrative privileges unless strictly necessary.
- If an installer script remains available, publish its source alongside the Skill and pin instructions to an immutable release rather than a mutable
install.shorinstall.ps1endpoint. - Replace the current instructions with a workflow similar to:
sh curl --proto '=https' --tlsv1.2 -fLo clawheart-installer.sh \ https://clawheart.live/releases/VERSION/install.sh echo 'EXPECTED_SHA256 clawheart-installer.sh' | sha256sum -c - less clawheart-installer.sh sh clawheart-installer.shThe actual release version and digest must be fixed, authentic, and maintained securely. On Windows, use an equivalent download, Authenticode or checksum verification, review, and separate execution process rather than
Invoke-Expression.- Remove all direct download-and-execute patterns, including
