T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:43- Finding
Unpinned Remote Repository Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 43–46
Vulnerability Type: Unverified remote payload retrieval and insecure dependency installation
Risk Level: HighVulnerable Code Snippet:
bash git clone https://github.com/openclaw-skills/ai-intelligent-knowledge-qa cd ai-intelligent-knowledge-qa pip install -r requirements.txt python app.pyTechnical Analysis
The project contains only
SKILL.md; the application source, dependency manifest, and executable entry point are not included in the audited artifact. The installation instructions instead direct users to clone a mutable external Git repository, install the dependencies specified by that repository, and execute itsapp.py.The repository is not pinned to a reviewed commit or immutable release. No checksum, cryptographic signature, or other integrity verification is required before execution. The effective application payload can therefore change after this Skill has been reviewed.
Running
pip install -r requirements.txtalso delegates trust to dependencies selected by the remote repository. Python package installation can execute package build or installation hooks. Because neither the remoterequirements.txtnor its resolved dependency set was present in the audited artifact, their safety, version pinning, and package sources could not be verified.Attack Path
- An attacker compromises the referenced GitHub repository, gains control of a dependency, or causes a malicious update to be accepted upstream.
- The attacker modifies
app.py,requirements.txt, or another imported file to contain attacker-controlled code. - A user follows the documented installation procedure without receiving any warning that the retrieved content differs from the version originally reviewed.
pip install -r requirements.txtmay execute malicious package installation hooks.python app.pyexecutes the remotely supplied ap ...[truncated 785 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete application source and dependency manifest in the Skill package so the executed implementation is part of the reviewed artifact.
- If remote retrieval is unavoidable, pin the repository to a specific reviewed commit hash rather than cloning the mutable default branch.
- Verify downloaded content using a trusted cryptographic signature or a securely distributed checksum before installation or execution.
- Pin every Python dependency to an exact version and use a lock file containing package hashes, such as hashes enforced through
pip --require-hashes. - Restrict dependency installation to trusted package indexes and review transitive dependencies for dependency-confusion and typosquatting risks.
- Separate retrieval, verification, installation, and execution into explicit steps. Do not automatically execute newly downloaded code.
- Run the application under a dedicated, least-privileged account or isolated container with minimal filesystem, credential, and network access.
- Document all required permissions, external services, network destinations, and sensitive configuration before users execute the application.
