T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–19
Vulnerability Type: Unpinned npm supply-chain dependency
Risk Level: Mediumyaml requires: bins: ["mcporter"] env: ["ENGRAM_API_KEY"] install: - id: "node" kind: "node" package: "mcporter"Technical Analysis
The Skill declares installation of the
mcporternpm package without an exact version or integrity constraint. Consequently, the installed artifact can change after the Skill has been reviewed. A compromised maintainer account, malicious package update, or compromised transitive dependency could introduce arbitrary code into later installations.The package installation is necessary to provide the declared MCP client functionality, but accepting an unconstrained version exceeds the minimum supply-chain trust required. The audit found no evidence that the current package is malicious; the vulnerability is the absence of reproducible dependency controls.
Attack Path
- An attacker compromises the
mcporternpm package, a maintainer account, or a transitive dependency. - The attacker publishes a malicious release under the expected package name.
- OpenClaw processes the Skill requirement and installs the unconstrained package.
- Malicious installation lifecycle code or runtime code executes under the operator's account.
- The code may access files, environment variables, or network resources available to that account, including
ENGRAM_API_KEY.
Impact Assessment
Successful exploitation could result in arbitrary code execution with the privileges of the user running OpenClaw or the package installer. The accessible scope may include that user's files, environment variables, MCP configuration, and network credentials. The declaration does not itself request elevated operating-system privileges, so administrator or root access is not directly established.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
mcporterto an exact reviewed version rather than accepting the latest available release. - Where the installation framework permits it, verify the package using a lockfile or cryptographic integrity hash.
- Disable or restrict npm lifecycle scripts when they are not required.
- Review transitive dependencies and establish a controlled process for dependency upgrades.
- Confirm that the package comes from the intended publisher and official registry.
- Run the dependency with a restricted account or sandbox that cannot access unrelated files and credentials.
- Pin
