T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Executable Introduces Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4 and 76
Vulnerability Type: Unpinned and unauditable third-party dependency
Risk Level: MediumVulnerable Code
Line 4:
yaml metadata: {"openclaw":{"emoji":"🏦","requires":{"bins":["boj-mcp"]},"install":[{"id":"uv","kind":"uv","package":"boj-mcp","bins":["boj-mcp"],"label":"Install boj-mcp (uv)"}],"tags":["japan","boj","central-bank","monetary-policy","mcp","statistics","interest-rates","finance"]}}Line 76:
markdown - Python package: `pip install boj-mcp` or `uv tool install boj-mcp`Technical Analysis
The Skill directs the framework or user to install
boj-mcpfrom a third-party package registry without specifying an exact version, cryptographic hash, signature, or verified source repository. The project contains onlySKILL.md; therefore, the installed executable's implementation cannot be audited from the supplied artifact.Package installation can execute package-controlled build or installation logic, and subsequent documented commands execute the installed
boj-mcpbinary. Because the package reference is mutable, a compromised maintainer account, registry compromise, malicious future release, or dependency-confusion condition could cause code different from the reviewed behavior to be installed.The document also states that the tool performs network downloads and local caching. Those capabilities are not inherently malicious, but they increase the importance of verifying the external implementation and restricting its permissions.
Attack Path
- An attacker compromises the package publisher, distribution account, registry entry, or an upstream dependency used by
boj-mcp. - The attacker publishes a malicious release under the package name accepted by the unpinned installation declaration.
- A user or automation framework processes the Skill and runs
pip install boj-mcporuv tool install boj-mcp.
...[truncated 899 chars]
- An attacker compromises the package publisher, distribution account, registry entry, or an upstream dependency used by
- Remediation
View remediation
Remediation Suggestions
- Pin
boj-mcpto an exact, security-reviewed version in both the OpenClaw installation metadata and documented installation commands. - Require cryptographic hashes or verified package signatures where supported by the package manager.
- Document and verify the authoritative package registry and source-code repository rather than relying only on the package name.
- Review the package source, build configuration, transitive dependencies, network destinations, and local cache behavior before approving it.
- Generate and retain a lockfile or equivalent dependency manifest that includes all transitive versions and integrity data.
- Run the executable with least privilege, restricting filesystem access, credentials, environment variables, and outbound network access to what BOJ data retrieval requires.
- Use automated dependency monitoring and repeat the security review before updating the pinned version.
- Pin
