T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Mutable and Unpinned Third-Party Dependencies Create a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:12-15,README.md:50-62,references/guide.md:64-68
Vulnerability Type: Unpinned third-party dependencies and mutable installation sources
Risk Level: MediumVulnerable Code Snippets
SKILL.md:12-15:yaml install: - kind: uv package: ccxt pandas numpy ta label: "Install Python dependencies (ccxt, pandas, numpy, ta)"README.md:50-62:bash npx clawhub@latest install binance-signal-enginebash # Clone into your OpenClaw skills directory git clone https://github.com/eplt/binance-signal-engine.git \ ~/.openclaw/skills/binance-signal-engine # Install Python dependencies pip install ccxt pandas numpy tareferences/guide.md:64-68:bash Install all dependencies with: ```bash pip install ccxt pandas ta numpytext ### Technical Analysis The installation instructions do not pin exact versions or verify package integrity. The use of `@latest` expressly selects mutable code, while the Python installation commands resolve the newest compatible releases and transitive dependencies available at installation time. Consequently, the code installed on a future date may differ from the code that was reviewed. Potential exploitation mechanisms include: - Compromise of a legitimate package or publisher account. - Publication of a malicious future dependency release. - Registry or dependency-resolution manipulation. - Malicious installation hooks in a source distribution. - Compromise of the mutable ClawHub installer version selected by `@latest`. - Changes to the default branch fetched by the unpinned Git clone command. No evidence shows that the currently named dependencies are malicious. The vulnerability is the absence of reproducible version and integrity controls, which leaves installation behavior dependent on mutable third-party supply-chain state. ### Attack Path 1. An ...[truncated 1387 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin every direct Python dependency to an exact reviewed version, for example:
text ccxt==X.Y.Z pandas==X.Y.Z numpy==X.Y.Z ta==X.Y.Z -
Generate and commit a lockfile that also fixes all transitive dependency versions.
-
Require cryptographic hashes for Python artifacts, such as a hash-locked requirements file installed with:
bash pip install --require-hashes -r requirements.txt -
Replace
npx clawhub@latestwith an exact reviewed ClawHub CLI version. -
Pin manual Git installations to a reviewed release tag or commit hash rather than cloning a mutable default branch.
-
Verify release signatures or checksums where supported and use only explicitly trusted package registries.
-
Install dependencies in an isolated virtual environment with minimal filesystem and credential access.
-
Establish a dependency-update process that includes changelog review, vulnerability scanning, integrity regeneration, and testing before advancing pinned versions.
-
