T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:39- Finding
Unpinned Remote Repository Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39-44
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighVulnerable Code
bash git clone https://github.com/openclaw-skills/ai-intelligent-agent-platform cd ai-intelligent-agent-platform pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions clone a mutable remote Git repository without pinning a reviewed commit, tag, or cryptographically verified release. They subsequently install dependencies from an external
requirements.txtand executeapp.py.The audited project contains only
SKILL.md; neither the application source nor its dependency manifest is included. Therefore, the effective code and dependencies executed by these commands cannot be verified from the reviewed artifact and may change after the Skill has been audited. The execution chain also permits Python package installation mechanisms, including package build scripts, to run code during dependency installation.Attack Path
- An attacker compromises the referenced repository, gains control of its namespace, or introduces a malicious commit into its default branch.
- Alternatively, an attacker compromises or replaces a dependency referenced by the remote repository.
- A user follows the documented installation commands and clones the current, attacker-influenced repository state.
pip install -r requirements.txtinstalls the uncontrolled dependencies and may execute malicious package build or installation logic.python app.pydirectly executes the remotely obtained application code.- The malicious code runs with the permissions and environment access of the invoking user.
Impact Assessment
Successful exploitation can result in arbitrary code execution under the invoking user's account. The payload could access files, environment variables, credentials, network resources, and ...[truncated 415 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete, auditable implementation and dependency manifest in the distributed Skill package.
- If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than cloning a mutable default branch.
- Distribute signed releases and verify their cryptographic signatures or checksums before installation or execution.
- Lock all Python dependencies to exact versions and require hashes, such as through
pip install --require-hashes. - Review both direct and transitive dependencies and obtain them only from trusted package indexes.
- Separate download, verification, dependency installation, and application execution into distinct steps rather than executing remote code immediately.
- Run the application with a dedicated, least-privileged account in a sandbox or container with restricted filesystem, credential, and network access.
