T03 · Remote Payload Retrieval and Execution
- Location
README.md:143- Finding
Unverified Remote Installer Piped Directly into a Shell
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill mostly does what it says, but its Docker deployment and persistent configuration changes are broad enough that users should review them before installing.
Install only if you are comfortable with a persistent Docker SearXNG container, a SEARXNG_BASE_URL entry being written to ~/.zshrc, and a local port being exposed through Docker. Prefer pinning the SearXNG image, binding the port to 127.0.0.1, and avoiding the README curl-to-shell Docker install command.
README.md:143Unverified Remote Installer Piped Directly into a Shell
scripts/install.sh:113Automatically Executed Container Image Uses a Mutable Latest Tag
scripts/install.sh:119Local SearXNG Service Is Published on All Host Network Interfaces
scripts/env.sh:7Shell Profile Assignments Are Parsed with Broad Grep and Unsafe Word Splitting
The README instructs users to run curl -fsSL https://get.docker.com | sh, which combines remote content retrieval with immediate shell execution. If the remote endpoint, network path, or DNS/TLS trust chain is compromised, arbitrary code would run on the user’s system with the invoking user’s privileges.
The documented purpose emphasizes installation/deployment, but the skill also exposes destructive behaviors such as uninstalling, deleting local directories with rm -rf, and modifying ~/.zshrc. This mismatch is dangerous because users or orchestrators may invoke the skill expecting setup only, while hidden side effects can cause data loss or persistent environment changes.
The skill advertises shell-driven deployment behavior but does not declare any tool scope or allowed tools. In an agent environment, undeclared shell capability reduces transparency and can permit execution of system-modifying commands without clear policy gating or user awareness.
The trigger phrases are broad enough to match generic requests about search, hosting, or SearXNG, increasing the chance of accidental activation. In an agent system tied to shell execution, overbroad matching can lead to unintended Docker deployment and local configuration changes on loosely related prompts.
The usage description does not warn that execution will automate Docker deployment and modify OpenClaw/local environment configuration. Missing user warning undermines informed consent and makes accidental infrastructure changes more likely, especially in automated agent workflows.
The generated configuration hard-codes default_lang: zh-CN, which imposes a specific language/locale choice on users. Under the policy, locale constraints should be opt-in or clearly justified as region-specific, and this script does neither.
The installer performs persistent user-environment modification by configuring OpenClaw through the user's shell profile, which exceeds the narrowly expected scope of deploying a SearXNG container. Even though it is not overtly malicious, persistence in ~/.zshrc creates side effects outside the service itself and can silently influence future shells and other tooling that reads the variable.
The script persistently alters ~/.zshrc, which is not required to start SearXNG and grants the installer a broader configuration surface than its stated role. Persistent shell startup modification is security-relevant because it survives the install session, affects future interactive environments, and could be abused as a foothold for environment-based hijacking if the pattern is normalized.
The script's descriptive comment and all user-facing output are in Chinese, which imposes a specific language on users. There is no indication that the skill is intended only for a Chinese-speaking environment or that users can opt into another locale.
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- ✅ 新增幂等性检测(已安装时显示状态不重复部署)
- ✅ 新增卸载脚本 `uninstall.sh`
- ✅ 新增 `source ~/.zshrc` 生效提示
- ✅ 增强 curl 超时参数(--connect-timeout, --max-time)
- ✅ 停止旧容器逻辑(升级时清理)
## 故障排除
Remote code is downloaded and executed. This bypasses code review and could introduce malicious code.
- ✅ 新增幂等性检测(已安装时显示状态不重复部署)
- ✅ 新增卸载脚本 `uninstall.sh`
- ✅ 新增 `source ~/.zshrc` 生效提示
- ✅ 增强 curl 超时参数(--connect-timeout, --max-time)
- ✅ 停止旧容器逻辑(升级时清理)
## 故障排除
The skill description, triggers, and usage instructions are entirely in Chinese, which effectively forces a specific language experience without user opt-in. The file does not state that the skill is intended only for a Chinese-speaking audience or provide an alternative language option.
Lines L08-L10 read from ~/.zshrc to obtain SEARXNG_BASE_URL. Although the script is a status checker, this access to user configuration data is not disclosed to the user via a comment in the action area or a user-facing message before it happens.
The manifest describes a one-click deployment skill for self-hosted SearXNG, while this uninstall script also edits ~/.zshrc to remove an exported environment variable. Although related to prior setup, modifying persistent shell configuration goes beyond simply removing containers and deployment files and is not reflected in the manifest description.
No suspicious patterns detected.