T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned Third-Party Python Package Executes Unverified Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17-20andSKILL.md:39
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
yaml "package": "hefesto-ai", "bins": ["hefesto"], "label": "Install HefestoAI (pip)"bash pip install hefesto-aiTechnical Analysis
The Skill installs
hefesto-aiwithout pinning an exact version or verifying package integrity with a cryptographic hash. Consequently, installation resolves to whichever package version the configured Python package index currently supplies.The downloaded package provides the
hefestoexecutable and therefore controls the Skill's effective runtime behavior. This project contains onlySKILL.md; it does not include the executable implementation needed to independently verify the claims that analysis is local, read-only, and free of network activity.This is a supply-chain weakness rather than evidence that the currently published package is malicious. Exploitation would require compromise or malicious replacement of the package, one of its transitive dependencies, or the package source used by the environment.
Attack Path
- An attacker compromises the
hefesto-aipublishing account, a transitive dependency, or a configured Python package index. - The attacker publishes a malicious release under the package name expected by the Skill.
- OpenClaw or a user follows the installation metadata or documented command and runs
pip install hefesto-ai. - Because no exact version or integrity hash is required, pip retrieves the attacker-controlled release.
- Malicious code can execute during installation or when the supplied
hefestocommand is invoked. - The code then operates with the installing user's privileges and can access source files supplied for analysis and other resources available to that account.
Impact Assessment
Successful exploitation could p ...[truncated 587 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
hefesto-aito a specific, reviewed version in both the OpenClaw installation metadata and installation documentation. - Distribute a lock file or requirements file containing cryptographic hashes, and install it with pip's
--require-hashesoption. - Pin and hash all transitive dependencies, not only the direct package.
- Document and enforce a trusted package index rather than relying on arbitrary environment-level pip configuration.
- Link or vendor the auditable source corresponding exactly to the pinned release so that the privacy and read-only claims can be verified.
- Run the analyzer in a sandbox with read-only project mounts, restricted filesystem permissions, no unnecessary credentials, and network access disabled.
- Add release provenance or package-signature verification where supported, and update pinned versions only after security review.
- Pin
