T08 · Insecure Dependencies
- Location
claw.json:19- Finding
Unpinned Python Package Is Downloaded and Executed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
claw.json:19-24andSKILL.md:22-28
Vulnerability Type: Supply-chain exposure through an unpinned runtime dependency
Risk Level: MediumThe skill configures
uvxto download and execute thehypabasepackage without an exact version, integrity hash, lockfile, or bundled auditable implementation.Complete configuration from
claw.json:19-24:json "mcp": { "command": "uvx", "args": ["--from", "hypabase", "hypabase-memory"], "env": { "HYPABASE_DB_PATH": "hypabase.db" } },The same behavior is documented in
SKILL.md:22-28:json { "mcpServers": { "hypabase-memory": { "command": "uvx", "args": ["--from", "hypabase", "hypabase-memory"], "env": { "HYPABASE_DB_PATH": "hypabase.db" } }Technical Analysis
The
uvxcommand resolves the named Python package from an external package registry and executes itshypabase-memoryentry point. Becausehypabasehas no exact version constraint, each installation or invocation may resolve to a newer or otherwise different package release than the one originally reviewed.The project contains only
SKILL.mdandclaw.json; it does not contain the executable server implementation, a dependency lockfile, package hashes, or signature-verification policy. Consequently, the effective executable payload is outside the audited artifact and may change independently of it.Exploitation requires compromise or malicious modification of the resolved package or its dependency chain. The audit found no evidence that the package is currently malicious.
Attack Path
- An attacker compromises the package publication account, registry distribution path, or an unpinned transitive dependency.
- The attacker publishes a modified release that is eligible for resolution under the unrestricted package name.
- OpenClaw starts the configured MCP server.
- ` ...[truncated 1137 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
hypabaseto an explicitly reviewed, immutable version rather than resolving the latest compatible release. - Generate and retain a dependency lockfile covering the package and all transitive dependencies.
- Require cryptographic hashes for downloaded distributions and reject artifacts whose hashes do not match the reviewed values.
- Prefer vendoring the reviewed MCP implementation into the skill or distributing it as a signed, immutable artifact so its executable behavior is included in security review.
- Verify package provenance and publisher identity before updates, and review dependency changes before changing the pinned version.
- Run the MCP server in a sandbox with minimum filesystem and network access. Restrict it to the intended database path wherever practical.
- Use a dedicated low-privilege operating-system account and avoid exposing unrelated secrets through inherited environment variables.
- Apply equivalent version and integrity controls to every transitive dependency, not only the top-level
hypabasepackage.
- Pin
