T08 · Insecure Dependencies
- Location
SKILL.md:61- Finding
Unpinned npm Dependency Installed into the OpenClaw Application Directory
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:61-68; duplicated inreferences/windows-setup.md:42-53
Vulnerability Type: Unpinned executable dependency and unsafe supply-chain installation
Risk Level: MediumVulnerable Code
SKILL.md:61-68:powershell cd "D:\Program Files\OpenClaw\resources\openclaw" npm install node-llama-cppThe surrounding instructions state that the installation downloads precompiled binaries and that warnings and vulnerability notices may be ignored.
The same installation procedure appears in
references/windows-setup.md:42-53:powershell cd "D:\Program Files\OpenClaw\resources\openclaw" npm install node-llama-cppTechnical Analysis
The installation command does not specify an exact package version, lockfile, integrity digest, or verified package provenance. Consequently, npm resolves the dependency version available from the configured registry at installation time. The installed code may therefore differ from the code that existed when this Skill was reviewed.
npm packages can contain lifecycle scripts and native binaries that execute or load code on the user's system. Installing the package directly inside the OpenClaw application directory also permits dependency files to modify or influence the application's runtime environment. Advising users to ignore vulnerability warnings further reduces the likelihood that compromised or vulnerable transitive dependencies will be investigated.
Attack Path
- An attacker compromises the
node-llama-cpppackage, one of its transitive dependencies, its distribution account, or the registry used by the victim. - The attacker publishes a malicious version or replaces a downloaded native artifact.
- A user follows the Skill and runs the unpinned
npm install node-llama-cppcommand. - npm resolves the attacker-controlled release and downloads its package content and dependencies.
- Malicious li ...[truncated 935 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
node-llama-cppto an exact, reviewed version rather than relying on the latest registry-selected release. - Distribute a reviewed lockfile and use
npm ciso direct and transitive dependency versions are reproducible. - Verify package provenance, registry identity, signatures where supported, and expected integrity hashes before installation.
- Review package lifecycle scripts and native-binary download behavior before recommending the dependency.
- Do not instruct users to ignore vulnerability warnings. Document how warnings should be reviewed and define which findings, if any, are accepted with justification.
- Prefer an officially supported plugin or extension directory rather than modifying the packaged application directory.
- Perform installation with the least-privileged account capable of completing the task, and avoid an elevated shell unless strictly required.
- Consider disabling lifecycle scripts during initial acquisition with
--ignore-scripts, inspecting the package, and only enabling required build steps after verification.
- Pin
