T08 · Insecure Dependencies
- Location
SKILL.md:62- Finding
Unpinned Third-Party Package Installation Bypasses Environment Protections
- Content
View full analysis
/dev/null || pip install navil ``` Verification is limited to: ```bash navil --version ``` The fallback installation repeats the same unsafe pattern: ```bash pip3 install navil --break-system-packages 2>/dev/null || pip3 install navil ``` ### Technical Analysis The Skill installs `navil` from the configured Python package index without specifying an exact version or validating a cryptographic hash. Consequently, the code installed during Skill execution can differ from the code that existed when the Skill was reviewed. The `--break-system-packages` option bypasses Python's externally managed environment protection and permits modification of an interpreter environment managed by the operating system. Redirecting standard error to `/dev/null` also conceals warnings and diagnostics from the first installation attempt. The submitted project does not contain the `navil` package source or a lock file through which its implementation and transitive dependencies could be audited. The `navil --version` command confirms only that an executable is available; it does not establish package integrity or provenance. ### Attack Path 1. An attacker compromises the package-index account, distribution artifact, dependency, or package source used to resolve `navil`. 2. A user activates the Skill and follows its first-time setup instructions. 3. `pip` retrieves the current unpinned package and its transitive dependencies. 4. Package installation hooks or subsequently invoked package code execute with the privileges of the user running the agent. 5. The compromised package can access files and environment variables available to that user, alter the Python environment, or tamper with the OpenClaw configuration ...[truncated 592 chars]- Remediation
View remediation
/dev/null` so installation failures and security warnings remain visible. 5. Configure an explicitly trusted package index and verify package publisher provenance. 6. Bundle or reference auditable source corresponding exactly to the installed release. 7. Verify package integrity before invoking any `navil` command, rather than relying only on `navil --version`. ]]>
