T08 · Insecure Dependencies
- Location
SKILL.md:514- Finding
Unpinned Third-Party Skill Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:514,README.md:36, andREADME.md:42-43
Vulnerability Type: Unpinned dependency installation from mutable upstream sources
Risk Level: MediumRelevant code snippets:
SKILL.md:514bash Instalar con: `clawhub install latam-timezone-briefing`README.md:36bash clawhub install argentina-fiscal-calendarREADME.md:42-43bash git clone https://github.com/centriqs-ai/skills.git cp -r skills/argentina-fiscal-calendar ~/.openclaw/skills/Technical Analysis
The documented installation commands retrieve Agent Skill content from mutable upstream sources without pinning an audited package version or Git commit. They also do not verify a cryptographic checksum or signature before installing the retrieved content.
The
clawhub installcommands do not specify immutable versions. The Git installation procedure clones the repository's current default branch and immediately copies its contents into the user's Skill directory. Consequently, the content installed by a user may differ from the version reviewed during this audit.This is a supply-chain weakness rather than evidence that the currently audited files contain a malicious payload. Exploitation requires an upstream registry package, publisher account, repository, release process, or network delivery path to become compromised. The documented commands are not shown to run automatically.
Attack Path
- An attacker compromises an upstream publisher account, registry package, Git repository, or associated release process.
- The attacker publishes a modified Skill version containing malicious instructions or executable components.
- A user follows one of the documented unpinned installation commands.
- The package manager or Git retrieves the attacker-controlled current version rather than the audited revision.
- The content is copied into the local OpenCl ...[truncated 951 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every Skill installation to an explicit, audited release version rather than implicitly selecting the latest release.
- For Git-based installation, check out an immutable full commit hash before copying files:
bash git clone https://github.com/centriqs-ai/skills.git cd skills git checkout --detach FULL_AUDITED_COMMIT_HASH cp -r argentina-fiscal-calendar ~/.openclaw/skills/ - Publish SHA-256 checksums or signed release manifests and instruct users to verify them before installation.
- Cryptographically sign releases and verify signatures against a documented, independently distributed publisher key.
- Avoid copying directly from a repository's mutable default branch into an active Skill directory.
- Stage downloaded content in a review directory, inspect its instructions and scripts, and activate it only after verification.
- Apply the same version-pinning and integrity-verification requirements to recommended related Skills.
- Document the exact version or commit corresponding to the security-reviewed release.
