T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Skill Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15–16
Vulnerability Type: Unpinned and mutable third-party skill dependencies
Risk Level: MediumVulnerable Code
bash npx clawhub install doubao-video-analyzer npx clawhub install video-downloaderTechnical Analysis
The documented installation commands install third-party skills by name without specifying an exact version, immutable commit, cryptographic checksum, or verified artifact. Consequently, the code installed when users execute these commands can change after this skill has been reviewed.
These dependencies occupy security-sensitive positions in the workflow.
video-downloaderprocesses attacker-selectable URLs and creates local files, whiledoubao-video-analyzerruns with access to the process environment, includingARK_API_KEY, and processes local video content.reverse_video.pysubsequently imports or executes dependency code as part of ordinary operation.The project also imports a
douyin-downloadercomponent for Douyin URLs, although that runtime dependency is not declared in_meta.jsonor listed consistently among the documented prerequisites. This makes the complete dependency trust boundary less transparent.No evidence was found that the currently reviewed project intentionally compromises these dependencies. The vulnerability is the absence of controls ensuring that future installed dependency content is the same content that was reviewed.
Attack Path
- An attacker compromises the registry account, publishing process, repository, or distribution entry associated with one of the named skills.
- The attacker publishes a malicious replacement or update under the trusted dependency name.
- A user follows the documented installation command, which resolves the current mutable release because no version or integrity constraint is present.
- The user invokes
reverse_video.py. - The project imports ...[truncated 996 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin each required skill to an exact reviewed version or, preferably, an immutable commit or content digest.
- Verify downloaded artifacts using cryptographic checksums or registry signatures before installation.
- Record trusted publishers, source repositories, versions, and expected hashes in the project documentation and metadata.
- Add every runtime dependency—including the
douyin-downloadercomponent used for Douyin URLs—to_meta.jsonand the installation documentation. - Review dependency source code before approving version updates and use an automated lockfile or manifest-integrity check where supported.
- Run downloader and analyzer dependencies with least privilege, a restricted filesystem view, and only the environment variables they require.
- Avoid exposing
ARK_API_KEYto downloader processes that do not need it; construct a minimal subprocess environment rather than inheriting the entire parent environment. - Clearly disclose which external services receive video identifiers or video content, including TikHub and Volcano Engine Ark.
