T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:29- Finding
Unverified Remote Script Executed with Root Privileges
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent OpenClaw troubleshooting guide, but it recommends several high-impact commands without enough safeguards for ordinary users.
Review this skill before installing or using it. Prefer safer alternatives: download and verify remote setup scripts before running them, avoid sudo -E unless necessary, back up ~/.openclaw/config.yaml before resetting it, avoid persistent npm registry/proxy changes unless you trust them, and try graceful process termination before kill -9.
SKILL.md:29Unverified Remote Script Executed with Root Privileges
SKILL.md:53Unpinned Global Package Installation Through a Third-Party Registry
The chained pattern 'curl ... | sudo -E bash -' combines network retrieval, shell interpretation, and privileged execution in one step, removing opportunities for inspection or validation. This greatly increases the chance of arbitrary code execution if the remote content is tampered with or the source is spoofed.
brew install node@20
# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
# 验证
The direct 'rm ~/.openclaw/config.yaml' command is destructive and offers no confirmation, backup, or validation. Even though the path is specific, users may lose credentials and custom settings, and copy-paste execution normalizes unsafe deletion practices.
解决:
# 重置配置
rm ~/.openclaw/config.yaml
openclaw config init
The manifest description says the skill is suitable for "遇到错误的用户" (users who encounter errors), which is a very broad trigger condition with no constraints on product scope, error type, or invocation context. This could overlap with many ordinary troubleshooting situations and cause unintended activation because it does not clearly define when the skill should or should not be used.
The line "遇到错误不用慌,这里有你需要的解决方案" implies applicability whenever a user encounters an error, without specifying OpenClaw-only scope or boundaries. Because the activation framing is generic and lacks negative examples, it increases the risk of accidental invocation for unrelated issues.
The explicit use of 'sudo -E' preserves user environment variables while running a remote-fetched script as root, which can unintentionally pass sensitive or dangerous environment state into privileged execution. Combined with curl-to-bash, this materially raises the risk of privilege abuse or unintended code execution.
brew install node@20
# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
# 验证
The explicit use of 'sudo -E' preserves user environment variables while running a remote-fetched script as root, which can unintentionally pass sensitive or dangerous environment state into privileged execution. Combined with curl-to-bash, this materially raises the risk of privilege abuse or unintended code execution.
brew install node@20
# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
# 验证
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
# Ubuntu
curl -fsSL https://deb.nodesource.com/setup_20.x | sudo -E bash -
sudo apt-get install -y nodejs
# 验证
node --version # 应该显示 v20.x.x
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
解决:
# 不要用 sudo!修复 npm 权限
mkdir ~/.npm-global
npm config set prefix '~/.npm-global'
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.zshrc
source ~/.zshrc
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
解决:
# 不要用 sudo!修复 npm 权限
mkdir ~/.npm-global
npm config set prefix '~/.npm-global'
echo 'export PATH=~/.npm-global/bin:$PATH' >> ~/.zshrc
source ~/.zshrc
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
# 验证 DeepSeek API Key
curl https://api.deepseek.com/v1/models \
-H "Authorization: Bearer $API_KEY"
The config reset instructions delete a user configuration file without warning, backup guidance, or validation that the path is correct. This can cause loss of settings, credentials, and service configuration, especially if copied blindly by inexperienced users.
Using 'kill -9 ' without warning encourages force-terminating processes and can kill the wrong process or interrupt active work. SIGKILL prevents graceful shutdown and may corrupt state or lose unsaved data.
No suspicious patterns detected.