T08 · Insecure Dependencies
- Location
scripts/gen_bug_data.py:156- Finding
Unnecessary Execution of an Unbundled External Dependency
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gen_bug_data.py, lines 156–159
Vulnerability Type: Unsafe import and execution of an external, unbundled Python module
Risk Level: MediumVulnerable Code
python sys.path.insert(0, "/app/openclaw/skills/data-generator/scripts") try: from build_prompt import build_prompt prompt = build_prompt(args.correct_tool, instructions)Technical Analysis
The script prepends the absolute directory
/app/openclaw/skills/data-generator/scriptstosys.path, importsbuild_prompt, and invokes it. The imported component is not included in this project and could not be audited with the rest of the Skill.Python executes top-level module code during import. Therefore, importing
build_promptis itself a code-execution boundary, even before the imported function is called. Placing the external directory at index zero also gives it priority during module resolution.The dependency is unnecessary in the current implementation: the returned
promptis only used to print its length, while the JSONL records are subsequently constructed directly. This also conflicts with the documentation's statement that the Skill does not depend on the internal implementation ofdata-generator.Attack Path
- An attacker gains the ability to create or modify
/app/openclaw/skills/data-generator/scripts/build_prompt.py, such as through a compromised Skill installation, writable shared directory, or supply-chain compromise. - A user invokes
scripts/gen_bug_data.py. - The script places the external directory first in
sys.path. - Python loads the attacker-controlled
build_prompt.py. - Module-level payloads execute during import.
- The script then calls the attacker-controlled
build_prompt()function. - The payload operates with the same OS account, environment access, filesystem permissions, and process privileges as the generator.
Impact Assessment
Successful exploitation permits ar ...[truncated 435 chars]
- An attacker gains the ability to create or modify
- Remediation
View remediation
Remediation Suggestions
- Remove the external import and
build_prompt()call because the resulting value is not needed to generate the output. - Remove the
sys.path.insert()modification. - If this dependency is required in the future, package it as a normal, version-pinned dependency from a trusted source.
- Verify the dependency's integrity and provenance during installation.
- Ensure dependency directories are not writable by less-trusted users or processes.
- Avoid importing executable Python code from mutable shared Skill directories.
- Add automated tests confirming that JSONL generation succeeds without loading external Skill internals.
- Remove the external import and
