Back to skill

Security audit

Ai Intelligent Asset Lifecycle

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a Chinese-language description of an asset-management app, but its install steps tell users to run unpinned code from an external GitHub repository that is not included in the reviewed package.

Review the external GitHub repository before installing, prefer a pinned and verified commit or release, and run it only in an isolated environment without sensitive credentials or broad filesystem access. The package itself does not include the implementation it asks you to execute.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T03 · Remote Payload Retrieval and Execution

Error
Location
SKILL.md:43
Finding

Unverified Remote Payload Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 43–46
Vulnerability Type: Mutable remote code retrieval and execution without integrity verification
Risk Level: High

Vulnerable Code

bash
git clone https://github.com/openclaw-skills/ai-intelligent-asset-lifecycle
cd ai-intelligent-asset-lifecycle
pip install -r requirements.txt
python app.py

Technical Analysis

The installation instructions direct users to clone an external Git repository and immediately install its dependencies and execute its application. The repository is not pinned to a reviewed commit or immutable release, and no digital signature, checksum, or other integrity control is required.

The audited package contains only SKILL.md and skill.json; it does not contain the referenced requirements.txt or app.py. Consequently, the code ultimately installed and executed is outside the audited artifact and may change after review.

Running pip install -r requirements.txt can execute package installation or build logic. Running python app.py then directly executes code retrieved from the mutable repository. This creates a remote payload execution channel through which a compromised repository, modified default branch, or unsafe dependency could introduce arbitrary executable behavior.

Attack Path

  1. An attacker compromises the referenced repository, gains control of an authorized maintainer account, or otherwise causes malicious content to appear on its default branch.
  2. The attacker modifies app.py, requirements.txt, or a referenced dependency to contain malicious installation or runtime behavior.
  3. A user follows the documented installation commands without selecting a verified commit or checking payload integrity.
  4. pip install -r requirements.txt executes attacker-controlled package installation or build logic, or installs a malicious dependency.
  5. python app.py executes the remotely supplied application code.
  6. The payload opera ...[truncated 854 chars]
Remediation
View remediation

Remediation Suggestions

  1. Include all executable source code and dependency manifests in the reviewed Skill package so that the distributed implementation matches the audited content.
  2. If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than cloning a mutable default branch.
  3. Publish signed, immutable releases and verify their signatures or cryptographic checksums before installation or execution.
  4. Lock every Python dependency to an exact reviewed version and require package hashes, such as through a hash-locked requirements file and pip install --require-hashes.
  5. Review transitive dependencies and use trusted package indexes with controls against dependency confusion and typosquatting.
  6. Perform installation and execution in an isolated, least-privileged virtual environment or container without unnecessary credentials, host mounts, or network access.
  7. Add a verification step that aborts installation when the repository revision, release signature, or dependency hashes do not match approved values.
  8. Ensure future releases include the advertised implementation so reviewers can inspect app.py, dependency files, and relevant security controls directly.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

The description and title present the skill in Chinese only, with no note that the user can choose another language or that the skill is intended specifically for a Chinese-language audience. Under the language/locale policy, forcing a specific language without user opt-in can be a natural-language policy issue.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.