T08 · Insecure Dependencies
- Location
requirements.txt:1- Finding
Unpinned DashScope Dependency Permits Unreviewed Supply-Chain Changes
- Content
View full analysis
Vulnerability Details
File Location:
requirements.txt:1
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code
text dashscopeTechnical Analysis
The project declares
dashscopewithout an exact version constraint or package integrity hash. Consequently, each installation may retrieve a different package release from the configured Python package index. The installed code can therefore differ from the dependency version evaluated during this audit.Python packages can execute code during installation and are imported with the privileges of the user running
scripts/analyze.py. If a future DashScope release, its publishing account, or the configured package index is compromised, malicious package code could execute during installation or when this Skill importsdashscope.This finding concerns the absence of dependency pinning and integrity verification. The audited files contain no evidence that the current
dashscopepackage itself is malicious.Attack Path
- An attacker compromises the dependency publisher, package distribution channel, or a future package release.
- The attacker publishes a malicious or compromised
dashscopeversion. - A user installs the project dependencies using
requirements.txt. - Because no version or hash is enforced, the package manager retrieves the attacker-controlled release.
- Malicious code executes during package installation or when
scripts/analyze.pyimportsdashscope. - The code operates with the filesystem, network, environment, and account privileges of the user running the installation or Skill.
Impact Assessment
Successful exploitation could allow arbitrary code execution under the installing or executing user's account. Depending on that account's permissions, an attacker could access local files and credentials, including the DashScope API key stored in
~/.openclaw/openclaw.json, send network requests, alter project f ...[truncated 138 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin
dashscopeto a specifically reviewed version using an exact version constraint, for example:text dashscope==REVIEWED_VERSION -
Generate a locked dependency file containing cryptographic hashes for all direct and transitive dependencies.
-
Install dependencies with hash enforcement, such as:
bash python3 -m pip install --require-hashes -r requirements.txt -
Use a trusted package index or an internally controlled dependency mirror.
-
Run dependency vulnerability and provenance checks in CI before accepting updates.
-
Review and test dependency upgrades explicitly rather than allowing installation-time resolution to select an arbitrary newer version.
-
Install and execute the Skill in an isolated, least-privileged environment without access to unrelated user credentials or sensitive files.
-
