T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Installation of a Security-Sensitive Third-Party Skill
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 27
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet:
markdown 2. **Privy Skill Installed**: `clawhub install privy`The same unpinned command is repeated in the requirements at line 171:
markdown - Privy skill installed (`clawhub install privy`)Technical Analysis
The installation instructions identify the
privyskill only by package name. They do not pin an audited version or immutable integrity digest. Consequently, the installed artifact may change after this skill has been reviewed.The dependency is security-sensitive because the documentation expects it to manage wallets, sign transactions, and operate in an environment containing
PRIVY_APP_IDandPRIVY_APP_SECRET. The dependency's source is not included in the submitted project, so its behavior could not be audited.This is a supply-chain weakness rather than evidence that the current
privypackage is malicious. Exploitation requires the registry entry, publisher account, distribution channel, or dependency-resolution process to be compromised or otherwise return an unsafe artifact.Attack Path
- An attacker compromises the publisher account or package-distribution path for the mutable
privyskill, or causes the package name to resolve to an unsafe release. - A user follows the documented
clawhub install privyinstruction without selecting a reviewed version or validating an integrity digest. - The package manager installs the attacker-controlled or unexpectedly modified artifact.
- The dependency executes in the OpenClaw environment where Privy credentials and wallet workflows may be available.
- Malicious dependency behavior could attempt to capture credentials, alter wallet requests, substitute transaction recipients, or initiate unauthorized signing operations, subject to the runtime permissions ...[truncated 842 chars]
- An attacker compromises the publisher account or package-distribution path for the mutable
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically reviewed version rather than installing the mutable latest release.
- Require an immutable package digest, checksum, signature, or equivalent integrity constraint where supported.
- Document the verified publisher identity and canonical source repository.
- Review the exact dependency artifact before granting it access to Privy credentials or wallet operations.
- Use least-privilege Privy policies, including per-transaction and aggregate spending limits, approved-chain restrictions, contract allowlists, and recipient restrictions.
- Isolate the dependency from unrelated secrets and system resources.
- Add lockfiles or equivalent reproducible dependency metadata when the complete implementation is supplied.
- Establish a controlled update process that requires security review before changing the pinned dependency.
