T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:39- Finding
Mutable Remote Payload Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39-42
Vulnerability Type:T03: Remote Payload Retrieval and Execution
Risk Level: HighVulnerable Code:
bash git clone https://github.com/openclaw-skills/ai-intelligent-customer-segmentation cd ai-intelligent-customer-segmentation pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions retrieve an external Git repository without pinning it to a reviewed commit, signed tag, or integrity-verified release. They subsequently execute
app.pyfrom that repository. Neitherapp.pynor the remote repository's dependency manifest is included in the audited artifact.Consequently, the effective executable payload can change after this skill package has been reviewed. Whoever controls or compromises the referenced repository can modify the default branch and cause later installations to execute different code. The submitted artifact contains no directly embedded malicious payload, but its documented workflow crosses the audit boundary by obtaining and executing mutable remote code.
Attack Path
- An attacker compromises the referenced repository or gains authority to modify its default branch.
- The attacker adds malicious behavior to
app.pyor another imported module. - A user or agent follows the installation commands in
SKILL.md. git cloneretrieves the attacker-controlled revision without commit or integrity verification.python app.pyexecutes the changed payload.- The payload operates with the permissions and environmental access of the invoking user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's account. Depending on that account's privileges and environment, the payload could read or alter accessible files, access environment variables and credentials, initiate network connections, or tamper with local ...[truncated 176 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete executable implementation in the skill package so it is covered by review.
- If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than a mutable branch.
- Distribute signed, versioned releases and verify cryptographic signatures or checksums before execution.
- Require an explicit review step between downloading the repository and running any code.
- Execute the application in an isolated, least-privileged environment without unnecessary credentials, filesystem access, or network permissions.
- Document the exact reviewed source revision in both
SKILL.mdandskill.json.
