T03 · Remote Payload Retrieval and Execution
- Location
hooks/postinstall.py:81- Finding
Automatic Retrieval of an Unpinned and Unverified Remote Code Package
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill discloses memory features, but it also automatically downloads an unverified private add-on during installation and checks it at startup.
Review before installing. Use --no-hooks unless you explicitly trust the publisher and the CNB repository, and prefer a version that pins and verifies the private package. Treat the downloaded private component as separate executable code with possible native extensions and API access.
hooks/postinstall.py:81Automatic Retrieval of an Unpinned and Unverified Remote Code Package
_meta.json:42Security Metadata Incorrectly Denies Remote Code and Native-Extension Capabilities
The description says the skill will automatically pull a private enhancement package from a CNB repository after installation. The supplied code instead runs as an on-startup hook, checks a local 'src/privileged' directory, queries Git state and upstream commit information, writes a status log, and tells the user to run commands manually for install or update. This is a material description-behavior mismatch in both primary behavior and trigger timing. While the code does interact with Git remotes, it does not actually perform the declared automatic pull/install action.
The description claims post-install automatic behavior ('安装后自动从 CNB 仓库拉取私有增强包'), which would imply network access and install/automation logic. In the supplied code chunk, there is no such behavior: no hook registration, no subprocess/package manager invocation, no HTTP/git access, and no install-time execution. The code only re-exports interfaces and safe implementations, plus metadata including a URL for an optional private enhancement package. Therefore the declared description overstates capabilities and does not accurately represent the actual behavior of this code chunk.
The supplied code chunk is limited to an init.py that re-exports interface definitions. While this is consistent with an 'interface layer,' it does not implement or indicate any automatic installation-time hook, private package retrieval, or CNB repository interaction described in the declared purpose. Therefore the description materially overstates behavior present in this code chunk.
The description claims install-time automated behavior and pulling a private package from a CNB repository, which would imply automation hooks and likely network/repository access. The actual code does none of that: it is a pure abstract interface definition for memory storage operations. While the code is related to 'memory' at a high level, its primary purpose is substantially different from the declared description. Therefore this is a clear description-behavior mismatch.
The declared description emphasizes installation-time automation and automatic retrieval of a private package from a CNB repository. The supplied code only declares an abstract interface for memory/search operations and contains no implementation for hooks, package installation, repository access, or network communication. While the memory-related theme loosely overlaps, the primary described behavior is not represented by this code chunk, making this a material description-behavior mismatch.
There is a clear description-behavior mismatch. The description emphasizes installation-time automation and retrieval of private enhancement packages from a CNB repository. In contrast, the actual code is limited to an abstract interface for vector backend operations used in memory/search infrastructure. It neither implements hooks nor accesses external repositories or private packages. This is not merely an implementation detail omission; the primary stated capability is absent from the supplied code.
The description emphasizes an integration layer plus automated hooks that automatically retrieve a private enhancement package from a CNB repository after installation. The supplied code instead is a self-contained local implementation of memory storage and full-text search using SQLite. Its only 'triggers' are SQLite table triggers for maintaining the FTS index, which are unrelated to install-time automation hooks. There is no network access, repository interaction, package download, or private package integration. This is a clear description-to-behavior mismatch, with the actual code serving a different primary purpose.
The description emphasizes post-install automation and repository retrieval of a private package, implying network/repository access and install hooks. The actual code chunk is exclusively a test runner (unittest) for local modules under src/core, validating imports and basic behaviors such as ANN search, cosine similarity, NUMA/cache/IRQ/FMA/Kunpeng status checks, hugepage stats, and SQLite implementation detection. There are no triggers, package-install hooks, CNB interactions, network operations, or private package retrieval logic in this code. This is a material mismatch in primary purpose and capabilities.
The declared description claims an interface-layer and automation-hook component for LLM memory integration that automatically fetches a private enhancement package from a CNB repository after installation. The supplied code does none of that. It is strictly a local test file for CI/CD validation: it manipulates Python import paths, imports internal modules, checks package exports and class inheritance, prints status lines, and exits with success/failure. There is no network access, repository interaction, package installation logic, post-install trigger, or memory-integration functionality. This is a clear material mismatch in primary purpose and capabilities.
The document makes a materially misleading safety claim by labeling the public package as 'zero risk' and 'no network/subprocess use' while elsewhere documenting a postinstall hook that automatically performs a remote git clone. That behavior introduces network access, code retrieval, and likely subprocess execution at install time, which can conceal supply-chain risk from users and reviewers.
The explicit goal that 'users need not know the private package exists' is a major red flag because it normalizes covert acquisition of remote code unrelated to the visible public package boundary. In the context of an install/startup hook system, hidden retrieval of a private package materially increases supply-chain risk and undermines informed consent.
The documented behavior adds automatic cloning and deployment of a private package during installation, which materially expands the skill's effective behavior beyond what a normal public package description implies. Pulling additional code at install time introduces a supply-chain trust boundary and can bypass user expectations and some review controls applied only to the published package contents.
Advertising hidden post-install behavior as 'user-unnoticed' is especially dangerous because it frames stealthy environmental modification as a product advantage. In this context, the hidden action is remote code retrieval and deployment, which heightens the risk of covert supply-chain compromise and undermines informed consent.
The document claims the public package has 'no network access' while elsewhere stating that an install hook automatically clones a private package from a remote CNB repository. This is a materially misleading security claim that can cause reviewers and users to underestimate supply-chain and post-install execution risk, especially because the network activity occurs automatically during installation.
The skill declares powerful capabilities through metadata and lifecycle hooks, including network access, filesystem writes, and use of external binaries, but does not define a clear tool-scope/allowed-tools policy. Combined with automatic postinstall and startup execution that pulls a private package into a privileged path, this creates a supply-chain and arbitrary code execution risk with insufficient constraint visibility.
The manifest description includes Chinese-only text ('接口层 + 自动化钩子。安装后自动从 CNB 仓库拉取私有增强包。') while the rest of the skill metadata does not indicate that the skill is region-specific or that users can choose their preferred language. This creates a natural-language locale policy concern because the skill appears to impose a specific language without opt-in or justification.
The manifest explicitly advertises automatic post-install retrieval of a private package from a remote CNB repository, but does not define clear user consent, integrity verification, version pinning, or activation constraints. In this skill’s context, that is dangerous because the downloaded 'privileged' package extends functionality outside the reviewed manifest and is written into a privileged path, creating a supply-chain and hidden-capability risk.
The manifest explicitly advertises automatic post-install and startup hooks that fetch a private enhancement package from a remote CNB repository, while giving no activation constraints, integrity guarantees, or user-consent controls. In this skill context, that means installation can trigger hidden remote code introduction into a privileged local path, substantially increasing supply-chain and persistence risk.
Several user-facing manifest fields, including the main description and operational descriptions, are written in Chinese with no indication that the user can choose another language. For a general-purpose skill manifest, this constitutes a language/locale policy concern because it imposes a specific language without opt-in or documented justification.
The stated purpose of the skill is an interface layer, but the documented design goal is to let users unknowingly receive a private enhancement package via lifecycle hooks. That mismatch is a transparency and trust-boundary problem because it obscures that installation includes hidden remote retrieval and deployment beyond the apparent feature scope.
The documentation describes automatic network retrieval and deployment of a private package during installation but does not frame this with a strong user-facing warning about network access, code provenance, privilege implications, or filesystem modification. That omission increases the chance that users install the skill without understanding that installation changes system state and imports external code.
The document presents inconsistent statements about update behavior: it says updates are not automatically executed, but also describes automatic startup-time update checks and highlights automated update detection as a core advantage. Even if code is not auto-executed, silent background version checks still create undeclared network activity and can mislead users about system behavior.
Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.
检查:
# 查看私有包目录
ls -la ~/.openclaw/workspace/skills/llm-memory-integration/src/privileged/
# 查看状态日志
cat ~/.openclaw/workspace/skills/llm-memory-integration/.privileged_status.log
Describing the feature as requiring no user action and being 'unnoticed' while it silently retrieves and deploys a private package normalizes hidden installation-time behavior. That mismatch reduces informed consent and can conceal meaningful changes to the user's environment, increasing the risk of supply-chain abuse or unexpected code introduction.
The documentation promotes automatic network cloning and deployment during installation without an up-front warning proportionate to its impact. Users may install the skill believing it is a standard package, while it actually changes the system by downloading and deploying additional code from a remote source.
No suspicious patterns detected.