T03 · Remote Payload Retrieval and Execution
- Location
templates/install-node.sh:14- Finding
Unverified Remote Installer Is Piped Directly into Bash
- Content
View full analysis
/dev/null 2>&1; then echo "📦 安装 NVM..." curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.0/install.sh | bash export NVM_DIR="$HOME/.nvm" [ -s "$NVM_DIR/nvm.sh" ] && \. "$NVM_DIR/nvm.sh" fi ``` The installer is propagated into generated deployment packages by `scripts/build-portable.sh`, line 107: ```bash cp "$TEMPLATE_DIR/install-node.sh" "$OUTPUT_DIR/" 2>/dev/null || echo " ⚠️ install-node.sh 模板不存在" ``` ### Technical Analysis The script downloads content from an external URL and immediately pipes it into Bash. Although the URL refers to the recognized `nvm-sh/nvm` GitHub repository and specifies the `v0.40.0` tag, the retrieved bytes are not authenticated through a checksum or cryptographic signature. The effective code executed by the Skill is therefore not fully contained in the audited package. Compromise of the upstream repository, release reference, hosting infrastructure, TLS trust environment, or network path could cause different code to execute after the Skill has already been reviewed. The script also omits defensive download options such as `--fail`, so it does not explicitly require a successful HTTP status before passing the response body to Bash. The documented deployment workflow directs users to run this installer, making the vulnerable operation part of the expected usage path. Direct remote execution is not required for the declared portable deployment functionality. Node.js can be installed through a trusted system package manager, or an installer can be downloaded and verified before execution. ### Attack Path 1. A user builds or receives an OpenClaw portable deployment package. 2. The package includes the copied `install-node.sh` template. 3. The user follows the deployment instructions and ru ...[truncated 911 chars]- Remediation
View remediation
