T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:39- Finding
Unpinned Remote Payload and Dependency Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39–42
Vulnerability Type: Remote payload retrieval and insecure dependency execution
Risk Level: MediumComplete Code Snippet:
bash git clone https://github.com/openclaw-skills/ai-intelligent-live-streaming-assistant cd ai-intelligent-live-streaming-assistant pip install -r requirements.txt python app.pyTechnical Analysis
The documented installation procedure clones a mutable external Git repository without specifying a reviewed commit hash or immutable release tag. It then installs dependencies from a remote-controlled
requirements.txtand executesapp.py.Neither
requirements.txtnorapp.pyis included in the audited package. Their contents therefore could not be reviewed, and the effective payload is determined by the external repository at installation time. Changes to that repository after this audit would directly change the code and dependencies executed by users.The dependency installation also lacks version and integrity controls in the reviewed instructions. There is no evidence of pinned package versions, cryptographic hashes, lock-file verification, or provenance validation. This creates a supply-chain exposure in addition to the mutable remote-code risk.
Attack Path
- An attacker compromises the referenced repository, a maintainer account, or the repository's dependency manifest.
- The attacker modifies
app.py,requirements.txt, or related repository content to introduce a malicious payload. - A user follows the installation instructions and clones the repository's current state.
pip install -r requirements.txtinstalls attacker-controlled or substituted dependency code, potentially running package build or installation hooks.python app.pydirectly executes the remotely supplied application.- The payload operates with the privileges of the user who ran the commands.
Impact Asse
...[truncated 572 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the complete application source, dependency manifest, and relevant installation scripts in the auditable Skill package.
- If remote retrieval is unavoidable, check out an immutable, reviewed commit hash rather than the repository's mutable default branch.
- Verify downloaded source using a trusted cryptographic digest or a signed release before installation or execution.
- Pin every direct and transitive Python dependency to an approved version and require hashes, such as through a hash-locked requirements file.
- Use a reproducible lock file generated from a reviewed dependency set, and continuously scan dependencies for known vulnerabilities and package-name substitution risks.
- Separate download, verification, dependency installation, and execution into distinct steps. Do not instruct users to execute newly downloaded code before inspection.
- Install and run the application in an isolated virtual environment or container under a dedicated, least-privileged account.
- Document the required filesystem, credential, and network permissions so users can restrict the application's execution scope.
