T08 · Insecure Dependencies
- Location
scripts/setup.sh:81- Finding
Unpinned Packages Are Installed from Mutable External Registries
- Content
View full analysis
Vulnerability Details
File Location:
scripts/setup.sh:81-84,scripts/watchdog.py:211-218,openclaw-watchdog/scripts/setup.sh:68-71,openclaw-watchdog/scripts/watchdog.py:211-218
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code
bash info "Setting up Python virtual environment" python3 -m venv "$VENV_DIR" "$VENV_DIR/bin/pip" install --quiet --upgrade pip "$VENV_DIR/bin/pip" install --quiet aiohttppython log.info("User approved reinstall, running npm install -g openclaw...") APPROVE_REINSTALL.unlink(missing_ok=True) await send_telegram(session, cfg, "🔧 <b>Watch Dog:</b> Reinstalling OpenClaw (approved by user)...") try: subprocess.run(["npm", "install", "-g", "openclaw"], timeout=120, capture_output=True, text=True) await asyncio.sleep(5) subprocess.run(["openclaw", "gateway", "start"], timeout=30, capture_output=True, text=True)Technical Analysis
The setup script upgrades
pipand installs the latest resolvableaiohttppackage without an exact version or integrity hash. The recovery routine similarly installs the currentopenclawrelease globally from npm without specifying a known-good version or verifying package integrity.No malicious package was identified during this static audit. The vulnerability is that the effective installation payload can change after the Skill has been reviewed. A compromised registry account, malicious upstream release, dependency compromise, or unexpected breaking release could cause arbitrary package installation code to execute under the user's account.
The npm operation requires explicit approval through
~/.openclaw/watchdog/approve-reinstall, which reduces the likelihood of exploitation but does not protect the integrity of the downloaded package.Attack Path
- An attacker compromises an upstream ...[truncated 1110 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
aiohttpand all transitive dependencies to reviewed versions. - Use a lockfile or requirements file with cryptographic hashes, such as
pip install --require-hashes -r requirements.txt. - Do not upgrade
pipautomatically during installation; use a tested minimum version and fail with clear instructions if it is unavailable. - Record the currently installed OpenClaw version and reinstall that exact known-good version rather than the unconstrained latest release.
- Verify npm package provenance or integrity before installation.
- Prefer a user-scoped, isolated installation over
npm install -g. - Require renewed, operation-specific user confirmation that displays the exact package version and source before reinstalling.
- Check subprocess return codes before claiming recovery succeeded.
- Pin
