T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:42- Finding
Unpinned Remote Payload Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 42–45
Vulnerability Type: Remote payload retrieval and execution
Risk Level: Highbash git clone https://github.com/openclaw-skills/ai-intelligent-defect-detection cd ai-intelligent-defect-detection pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions clone the default branch of an external Git repository without pinning it to a reviewed commit, tag digest, or cryptographically verified artifact. They then install dependencies selected by the remote
requirements.txtand execute the remoteapp.py.The local package contains only
SKILL.mdandskill.json; it does not include the advertised application implementation,app.py, orrequirements.txt. Consequently, the code ultimately installed and executed is outside the audited artifact and can change after review. A compromise of the repository, its maintainers, or its dependencies could therefore replace the effective payload without modifying this Skill package.Attack Path
- An attacker gains control of, or contributes malicious content to, the referenced repository or one of its dependencies.
- The attacker modifies the default branch,
requirements.txt,app.py, or a transitively installed package. - A user or agent follows the documented installation instructions.
git cloneretrieves the attacker-controlled revision.pip install -r requirements.txtinstalls remotely selected packages and may run package build or installation logic.python app.pydirectly executes the retrieved application code with the invoking user's privileges.
Impact Assessment
Successful exploitation permits arbitrary code execution under the account running the commands. The payload could read or alter files accessible to that account, access environment variables and credentials, make network requests, tamper with project data, or ...[truncated 235 chars]
- Remediation
View remediation
Remediation Suggestions
- Package the reviewed implementation and required resources directly within the Skill artifact.
- If remote retrieval is unavoidable, pin the repository to an immutable, reviewed commit hash rather than cloning a mutable default branch.
- Verify downloaded content using an expected cryptographic hash or trusted signature before installation or execution.
- Pin every Python dependency to an exact version and require hashes, such as through a lock file and
pip install --require-hashes. - Review direct and transitive dependencies and use trusted package indexes explicitly.
- Avoid immediately executing newly downloaded code. Separate retrieval, verification, installation, and execution into distinct approval steps.
- Run the application in a least-privilege sandbox or container with restricted filesystem access, credentials, and outbound networking.
