T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Unverified Remote Payload Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–46
Vulnerability Type: Mutable remote code retrieval and execution without integrity verification
Risk Level: HighVulnerable Code
bash git clone https://github.com/openclaw-skills/ai-intelligent-asset-lifecycle cd ai-intelligent-asset-lifecycle pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions direct users to clone an external Git repository and immediately install its dependencies and execute its application. The repository is not pinned to a reviewed commit or immutable release, and no digital signature, checksum, or other integrity control is required.
The audited package contains only
SKILL.mdandskill.json; it does not contain the referencedrequirements.txtorapp.py. Consequently, the code ultimately installed and executed is outside the audited artifact and may change after review.Running
pip install -r requirements.txtcan execute package installation or build logic. Runningpython app.pythen directly executes code retrieved from the mutable repository. This creates a remote payload execution channel through which a compromised repository, modified default branch, or unsafe dependency could introduce arbitrary executable behavior.Attack Path
- An attacker compromises the referenced repository, gains control of an authorized maintainer account, or otherwise causes malicious content to appear on its default branch.
- The attacker modifies
app.py,requirements.txt, or a referenced dependency to contain malicious installation or runtime behavior. - A user follows the documented installation commands without selecting a verified commit or checking payload integrity.
pip install -r requirements.txtexecutes attacker-controlled package installation or build logic, or installs a malicious dependency.python app.pyexecutes the remotely supplied application code.- The payload opera ...[truncated 854 chars]
- Remediation
View remediation
Remediation Suggestions
- Include all executable source code and dependency manifests in the reviewed Skill package so that the distributed implementation matches the audited content.
- If remote retrieval is necessary, pin the repository to a specific reviewed commit hash rather than cloning a mutable default branch.
- Publish signed, immutable releases and verify their signatures or cryptographic checksums before installation or execution.
- Lock every Python dependency to an exact reviewed version and require package hashes, such as through a hash-locked requirements file and
pip install --require-hashes. - Review transitive dependencies and use trusted package indexes with controls against dependency confusion and typosquatting.
- Perform installation and execution in an isolated, least-privileged virtual environment or container without unnecessary credentials, host mounts, or network access.
- Add a verification step that aborts installation when the repository revision, release signature, or dependency hashes do not match approved values.
- Ensure future releases include the advertised implementation so reviewers can inspect
app.py, dependency files, and relevant security controls directly.
