T08 · Insecure Dependencies
- Location
scripts/requirements.txt:1- Finding
Unpinned Third-Party Dependencies Are Installed from the Ambient Package Index
- Content
View full analysis
=5.9.5 pyautogui>=0.9.54 pycaw>=20240210 pywin32>=308 pywin32-ctypes>=0.2.2 pywinauto>=0.6.8 pillow>=10.4.0 emoji>=2.14.1 sounddevice>=0.5.1 soundfile>=0.13.1 packaging>=23.2 ``` `metadata.openclaw.yaml:46-54`: ```yaml setup: check_requirements: script: scripts/check_requirements.py cwd: . output_format: json success_key: missing_package run_once: true on_missing: action: install command: pip install -r scripts/requirements.txt ``` `SKILL.md:43-51`: ```bash python scripts/check_requirements.py ``` ```bash pip install -r scripts/requirements.txt ``` ### Technical Analysis The dependency manifest uses minimum-version constraints rather than exact, reviewed versions. Consequently, pip may install any future release satisfying the constraints. The installation command also lacks hash verification, an explicitly trusted package index, and an isolated environment requirement. Python packages can execute code during installation through build backends and later during import. Therefore, compromise of an allowed package release, its publisher account, a configured package index, or the local pip configuration could introduce code that was not present during this audit. This finding does not establish that any currently named dependency is malicious. The vulnerability is the absence of controls that bind installation to reviewed artifacts. ### Attack Path 1. The Skill runs `scripts/check_requirements.py` during initial setup. 2. One or more dependencies are reported as missing. 3. The agent follows the documented setup workflow and executes: `pip install -r scripts/re ...[truncated 931 chars]- Remediation
View remediation
pyautogui== ``` 2. Generate and verify cryptographic hashes for every package and transitive dependency. 3. Install with hash enforcement: ```bash python -m pip install --require-hashes -r scripts/requirements.txt ``` 4. Use a controlled, authenticated package mirror or explicitly document an approved index rather than relying on ambient pip configuration. 5. Install dependencies inside a dedicated virtual environment with no unnecessary privileges. 6. Maintain a lock file that includes transitive dependencies and review updates before changing it. 7. Add automated dependency scanning and provenance checks to the release process. ]]>
