T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:41- Finding
Mutable Remote Repository Retrieved and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 41–44
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Mediumbash git clone https://github.com/openclaw-skills/ai-intelligent-cv-platform cd ai-intelligent-cv-platform pip install -r requirements.txt python app.pyTechnical Analysis
The packaged skill contains no local implementation of its advertised computer-vision functionality. Instead, its installation procedure directs users to clone a mutable external Git repository, install dependencies from an unaudited
requirements.txt, and execute an unauditedapp.py.The repository is not pinned to an immutable commit, release artifact, or cryptographically verified digest. Consequently, the code executed by a user can differ from the code present when this skill was reviewed. Both Python package installation and application startup are code-execution channels: dependencies may execute build or installation hooks, while
python app.pydirectly runs the retrieved application with the invoking user's privileges.No malicious payload was present in the audited package, and compromise of the referenced repository or its dependencies was not established. The risk arises from delegating execution to mutable content outside the reviewed artifact and without integrity controls.
Attack Path
- An attacker compromises the referenced GitHub repository, gains control of an upstream dependency, or causes a malicious future revision to be published.
- The attacker adds malicious behavior to
app.py,requirements.txt, or a dependency installation hook. - A user follows the documented instructions and clones the current mutable repository state.
pip install -r requirements.txtexecutes package installation logic, orpython app.pyexecutes the modified application.- The payload runs with the permissions and environment access of the invoking user.
Impact Assessment
Successful exploitation could ...[truncated 448 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the reviewed application code and dependency manifest directly in the skill package so its effective behavior is covered by the audit.
- If external retrieval is unavoidable, pin the repository to a specific immutable commit rather than cloning the mutable default branch.
- Verify retrieved content against a trusted cryptographic digest or signed release before installation or execution.
- Pin every Python dependency to an exact version and use a lock file containing package hashes, such as hashes enforced through
pip --require-hashes. - Obtain packages only from explicitly configured, trusted indexes and review transitive dependencies and installation hooks.
- Run the application in a restricted virtual environment or container with minimal filesystem access, no unnecessary credentials, limited network access, and no administrative privileges.
- Document the application's required permissions, network destinations, data handling, and model-download behavior.
- Add automated dependency, provenance, and source-code scanning to the release process, and repeat the audit whenever the pinned repository revision or dependency lock file changes.
