T08 · Insecure Dependencies
Warning
- Location
SKILL.md:24- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–43
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumVulnerable Code
markdown 4. Use `"$PYTHON" -m pip ...` for package installation. ### Install packages ```bash "$PYTHON" -m pip install -U package_name "$PYTHON" -m pip install -U openai-whisper torch ffmpeg-pythontext ### Technical Analysis The skill instructs the agent to install or upgrade packages without fixed versions, integrity hashes, a lockfile, or an explicitly approved package index. The `-U` option actively selects newer available releases, making the executed dependency set mutable after the skill has been reviewed. Package installation may execute package build hooks or other attacker-controlled code. Installed packages may also execute code when subsequently imported. Exploitation would require compromise of a named package, one of its transitive dependencies, a package-index account, or the package index configured in the runtime environment. Dependency confusion may also be possible when a placeholder or internal package name is resolved through an untrusted public index. ### Attack Path 1. An attacker publishes or compromises a package or transitive dependency that pip can resolve under a requested name. 2. The agent follows the documented command and invokes `"$PYTHON" -m pip install -U` without version or hash verification. 3. Pip resolves the mutable attacker-controlled release through the configured package index. 4. Malicious code executes during package building or installation, or later when the installed package is imported. 5. The code operates with the same operating-system identity, filesystem access, network access, and environment-variable visibility as the OpenClaw process. ### Impact Assessment Successful exploitation can provide arbitrary code execution under the privileges of the agent process. The attacker could access or modify files available to ...[truncated 337 chars]- Remediation
View remediation
Remediation Suggestions
- Replace unconstrained installations with exact, reviewed version pins, such as
package_name==X.Y.Z. - Maintain a lockfile containing all direct and transitive dependency versions.
- Require cryptographic hashes for artifacts, using pip's
--require-hashesmode where practical. - Configure an explicitly approved package index and prevent unintended fallback to public or user-controlled indexes.
- Remove routine use of
-U; upgrades should be deliberate, reviewed changes. - Require explicit user approval before installing or upgrading packages.
- Install dependencies in an isolated virtual environment or container with minimal filesystem and network permissions.
- Prefer prebuilt, internally mirrored artifacts that have undergone malware and provenance checks.
- Replace unconstrained installations with exact, reviewed version pins, such as
