T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Mutable Remote Code Is Retrieved and Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43-46
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash git clone https://github.com/openclaw-skills/ai-intelligent-email-automation cd ai-intelligent-email-automation pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions direct users to clone a separate remote repository and execute its application. The repository is not pinned to a specific commit, signed release, or immutable artifact. As a result, the code executed by users can differ from the content present when this skill was audited.
Neither
app.pynorrequirements.txtis included in the audited artifact, which contains onlySKILL.mdandskill.json. Their behavior and dependencies therefore cannot be verified from this package. The subsequentpip installalso installs unspecified remote dependencies without visible version constraints or integrity hashes.This is primarily remote payload retrieval and execution: mutable external code becomes the effective implementation after review. The unverified dependency installation further increases supply-chain exposure.
Attack Path
- A user follows the installation instructions in
SKILL.md. - Git retrieves the current contents of the externally hosted repository rather than an audit-pinned revision.
- An attacker who compromises the repository, a maintainer account, or its distribution path modifies
app.pyorrequirements.txt. - The user installs the remotely specified Python packages through
pip install -r requirements.txt. - The user runs
python app.py, executing the unreviewed payload with the privileges of the current account. - The payload can access resources available to that account. If users configure the advertised SMTP/IMAP functionality, this may include email credentials and message data.
...[truncated 679 chars]
- A user follows the installation instructions in
- Remediation
View remediation
Remediation Suggestions
- Include the complete implementation and dependency manifest inside the audited skill package so reviewers can inspect the code that will execute.
- If external retrieval is unavoidable, pin the repository to a specific reviewed commit hash rather than cloning the mutable default branch.
- Distribute the application through a signed release and verify its cryptographic signature or checksum before installation or execution.
- Pin all Python dependencies to exact versions in a lock file and require package hashes, such as with
pip install --require-hashes. - Review direct and transitive dependencies for compromised, typosquatted, or abandoned packages.
- Run the application with a dedicated least-privileged account or sandbox, restricting filesystem and network access to only what is required.
- Document all required SMTP/IMAP permissions, credential-storage behavior, external connections, and email-data handling.
- Do not request or load production email credentials until the downloaded code and dependencies have passed integrity and security verification.
