Back to skill

Security audit

Python Env Setup

Security checks for vulnerabilities and agentic risk

Overview

This skill gives straightforward host-specific Python command guidance, with a minor supply-chain caution around unpinned pip install examples.

Before installing, confirm that PYTHON points to the intended interpreter and approve package installs deliberately. Prefer pinned package versions or a project lockfile when using the pip examples.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:24
Finding

Unpinned Third-Party Package Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 24–43
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

markdown
4. Use `"$PYTHON" -m pip ...` for package installation.

### Install packages

```bash
"$PYTHON" -m pip install -U package_name
"$PYTHON" -m pip install -U openai-whisper torch ffmpeg-python
text

### Technical Analysis

The skill instructs the agent to install or upgrade packages without fixed versions, integrity hashes, a lockfile, or an explicitly approved package index. The `-U` option actively selects newer available releases, making the executed dependency set mutable after the skill has been reviewed.

Package installation may execute package build hooks or other attacker-controlled code. Installed packages may also execute code when subsequently imported. Exploitation would require compromise of a named package, one of its transitive dependencies, a package-index account, or the package index configured in the runtime environment. Dependency confusion may also be possible when a placeholder or internal package name is resolved through an untrusted public index.

### Attack Path

1. An attacker publishes or compromises a package or transitive dependency that pip can resolve under a requested name.
2. The agent follows the documented command and invokes `"$PYTHON" -m pip install -U` without version or hash verification.
3. Pip resolves the mutable attacker-controlled release through the configured package index.
4. Malicious code executes during package building or installation, or later when the installed package is imported.
5. The code operates with the same operating-system identity, filesystem access, network access, and environment-variable visibility as the OpenClaw process.

### Impact Assessment

Successful exploitation can provide arbitrary code execution under the privileges of the agent process. The attacker could access or modify files available to 
...[truncated 337 chars]
Remediation
View remediation

Remediation Suggestions

  • Replace unconstrained installations with exact, reviewed version pins, such as package_name==X.Y.Z.
  • Maintain a lockfile containing all direct and transitive dependency versions.
  • Require cryptographic hashes for artifacts, using pip's --require-hashes mode where practical.
  • Configure an explicitly approved package index and prevent unintended fallback to public or user-controlled indexes.
  • Remove routine use of -U; upgrades should be deliberate, reviewed changes.
  • Require explicit user approval before installing or upgrading packages.
  • Install dependencies in an isolated virtual environment or container with minimal filesystem and network permissions.
  • Prefer prebuilt, internally mirrored artifacts that have undergone malware and provenance checks.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.