T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:75- Finding
Server-Controlled Update Command Can Be Executed Locally
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This subtitle extraction skill has a plausible purpose, but it asks for cloud credentials in chat, logs sensitive request data, and can run a server-provided update command.
Review carefully before installing. Use only least-privilege, short-lived credentials; do not paste long-lived AK/SK secrets into chat; avoid running the self-update path; and treat local logs under /tmp/openclaw as potentially sensitive because they may contain authorization headers, request data, response data, and media metadata.
SKILL.md:75Server-Controlled Update Command Can Be Executed Locally
scripts/core/api/iccp/client.py:124Cloud Credentials Are Exposed in Chat, Command Output, and Persistent Logs
scripts/core/api/meida/chunks.py:168Environment-Controlled API Destination Can Receive Bearer Tokens and Video Data
scripts/core/api/meida/chunks.py:286Video Upload Unnecessarily Enumerates All Account Users
scripts/requirements.txt:1Mandatory Runtime Installation Uses Mutable, Unhashed Dependencies
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
A workflow that actually performs upgrade/version tasks and remote status queries rather than subtitle extraction is materially outside the declared purpose. Hidden self-management capabilities are especially risky because they can change runtime behavior over time.
The skill explicitly instructs the agent to ask users to paste Volcengine ACCESS_KEY_ID and SECRET_ACCESS_KEY into chat, then exports and reuses them. Soliciting raw cloud credentials in a conversational channel is highly dangerous because it enables credential theft, accidental logging, replay, and broader compromise of the user's cloud account.
The instructions tell the agent to have users send AK/SK directly in chat and do not provide a strong warning against sharing secrets in chat. This normalizes insecure secret handling and substantially increases the chance of credential exposure in logs, transcripts, or downstream systems.
The skill not only requests cloud access keys in chat but also instructs the agent to export them into environment variables and reuse them for subsequent commands. This creates a direct path from conversational input to privileged command execution, magnifying the blast radius of any leak or misuse.
Referenced artifact was not completely inspected
python3.12 -m pip install -r ./scripts/requirements.txt
The skill includes a self-upgrade path that executes an install_command returned by a remote source after asking the user. Remote-controlled installation during skill execution is a supply-chain risk and can lead to arbitrary code execution if the update channel is compromised or the command is malicious.
The code logs full request metadata including headers and body before the request, which includes Authorization credentials in both the AK/SK signature flow and Bearer token flow, and may also include sensitive request payloads. It also logs full response headers and body, potentially exposing returned secrets or user data to application logs, which are often widely accessible and retained for long periods.
The skill calls IAM ListUsers and explicitly searches for an admin account ID, then falls back to the first user if no admin is found. For a subtitle-extraction skill, enumerating users and selecting an elevated owner context is unnecessary and dangerous because it broadens access scope and can cause media operations to run under a privileged identity unrelated to the requesting user.
This code implements remote media upload, remote material creation, and polling for uploaded asset metadata, which materially exceeds a subtitle-extraction skill’s declared purpose. In the context of a skill that should only extract subtitles, adding a general upload pipeline creates unnecessary data exfiltration and capability expansion risk, especially because arbitrary local media files are transmitted to a remote service.
The uploader is general-purpose and supports arbitrary image and video asset upload, with no evident restriction tying it to subtitle extraction. That broad capability meaningfully increases the attack surface because the skill can move unrelated local files to a remote platform and manage them as reusable materials, which is dangerous in a narrowly scoped media-processing skill.
No suspicious patterns detected.