T08 · Insecure Dependencies
- Location
SKILL.md:123- Finding
Unpinned Packages and Mutable Third-Party Skill Installations
- Content
View full analysis
Vulnerability Details
File Locations:
README.md:24-28README.md:34-37SKILL.md:54-59SKILL.md:75-81SKILL.md:123-161SKILL.md:339-341
Vulnerability Type: Supply-chain exposure through unpinned packages and mutable third-party Skills
Risk Level: MediumVulnerable Code
README.md:24-28:bash openclaw skills install 16miku/auto-remotion npx clawhub@latest install 16miku/auto-remotionREADME.md:34-37:bash npx create-video --yes --blank --no-tailwind my-video cd my-video npm install npm run devSKILL.md:54-59:bash npx create-video --yes --blank --no-tailwind my-video npx create-video@latestSKILL.md:123-161:bash npm i -g clawhub pnpm add -g clawhub openclaw skills install remotion-video-toolkit npx clawhub@latest install remotion-video-toolkit --force npx skills add remotion-dev/skillsSKILL.md:339-341:bash pip install -e video-use/helpers pip install requests librosa matplotlib pillow numpyTechnical Analysis
The documentation instructs users or AI agents to download and execute npm packages, Python packages, and third-party Skills without pinning exact versions, reviewed commit hashes, or integrity checks.
Commands using
npx ...@latestexplicitly resolve a mutable registry release at execution time. Other commands omit versions entirely, allowing package resolution to change after this Skill has been reviewed. The--forceoption additionally bypasses normal installation safeguards. Installing external Skills imports remotely maintained agent instructions that are outside the audited project and may change independently.npm packages can execute lifecycle scripts during installation, and packages invoked through
npxcan execute code immediately. Python packages can also execute build or installation logic. Consequently, compromise of an upstream package, publishe ...[truncated 1988 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every npm and Python dependency to an exact reviewed version rather than using
latestor an omitted version. - Pin repository-based Skill installations to immutable commit hashes whenever the installation tooling supports this.
- Commit and enforce package lockfiles, including npm integrity metadata, for generated or companion projects.
- Remove
--forcefrom installation instructions unless its necessity is documented and the user explicitly approves its use. - Require explicit user confirmation before installing any external package or Skill.
- Review third-party Skill contents before loading them into an agent session.
- Prefer locally vendored and audited helper scripts over runtime retrieval of mutable external content.
- Use isolated environments, such as containers, virtual environments, or restricted non-privileged accounts, for package installation and media processing.
- Disable package lifecycle scripts during initial inspection where practical, then enable only those required by reviewed packages.
- Add provenance or checksum verification and periodically audit pinned dependencies for known vulnerabilities.
- Pin every npm and Python dependency to an exact reviewed version rather than using
