T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party Dependency Installs Persistent OpenClaw Hooks
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9–50
Vulnerability Type: Unpinned and mutable third-party dependency installation
Risk Level: HighThe Skill instructs users to install the
mnemonexecutable from mutable external sources and then run an unattended setup command that deploys persistent OpenClaw hooks and extensions.yaml install: - id: "brew" kind: "brew" formula: "mnemon-dev/tap/mnemon" bins: ["mnemon"] label: "Install mnemon (Homebrew)" - id: "go" kind: "go" package: "github.com/mnemon-dev/mnemon@latest" bins: ["mnemon"] label: "Install mnemon (go install)"bash brew install mnemon-dev/tap/mnemonbash go install github.com/mnemon-dev/mnemon@latestbash mnemon setup --target openclaw --yestext This single command deploys all components: - Skill → ~/.openclaw/skills/mnemon/SKILL.md - Hook → ~/.openclaw/hooks/mnemon-prime/ (agent:bootstrap — injects behavioral guide) - Plugin → ~/.openclaw/extensions/mnemon/ (remind, nudge, compact hooks) - Prompts → ~/.mnemon/prompt/ (guide.md, skill.md)Technical Analysis
The Go installation explicitly selects
@latest, while the Homebrew instruction references a third-party tap without pinning an immutable version or verifying an artifact checksum or signature. The effective code installed by these commands can therefore change after this Skill has been reviewed.The downloaded executable is immediately trusted to run
mnemon setup --target openclaw --yes. The--yesoption suppresses interactive approval, and the setup operation writes an agent bootstrap hook, an extension, prompts, and a replacement or additional Skill outside the audited project. Those deployed components are not included in the artifact and consequently cannot be statically validated by this audit.No evidence in the reviewed file demonstrates that the curren ...[truncated 2027 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
github.com/mnemon-dev/mnemon@latestwith a reviewed, immutable release version or commit digest. - Pin the Homebrew installation to a reviewed release artifact where supported, and verify its cryptographic checksum or signature before execution.
- Publish release checksums through an independently protected channel and fail installation if verification does not succeed.
- Remove
--yesfrom the default setup instructions. Require explicit confirmation after displaying every file, hook, extension, prompt, and configuration entry that will be created or modified. - Vendor or include the exact hook, plugin, prompt, and generated Skill sources in the audited package so their behavior can be reviewed before installation.
- Apply least privilege during setup and runtime. The installer should reject elevated execution unless a narrowly scoped operation genuinely requires it.
- Make setup transactional, back up files before modification, and provide a manifest containing installed paths, versions, hashes, and rollback instructions.
- Reproducibly build releases and sign both release artifacts and update metadata using protected keys.
- Document the dependency update process and require security review before changing pinned versions or artifact hashes.
- Replace
