T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Third-Party Python Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:18-20and duplicate package declarations atSKILL.md:41-43
Vulnerability Type: Supply-chain risk caused by unconstrained dependency resolution
Risk Level: MediumVulnerable Code
yaml python_packages: - python-docx - lxmlThe same dependencies are also declared for automatic installation:
yaml pip: - python-docx - lxmlTechnical Analysis
The Skill declares
python-docxandlxmlwithout exact versions or cryptographic integrity hashes. If the hosting framework automatically installs these declarations, each installation resolves whichever compatible releases are available at that time. Consequently, the installed code can differ from the code originally reviewed.This creates a supply-chain exposure if a dependency release or package-distribution account is compromised. Python package installation and subsequent imports can execute package-controlled code under the identity running the Agent. The risk is especially relevant because this Skill processes resumes, contact information, employment histories, and local output files.
No evidence was found that the currently named packages are malicious. The vulnerability is the absence of reproducible, integrity-verified dependency resolution.
Attack Path
- An attacker compromises a declared dependency's distribution account or otherwise causes a malicious release to be served by the configured package index.
- The Skill framework installs dependencies from the unconstrained
pipdeclarations. - Dependency installation or import executes attacker-controlled Python code with the Agent process's permissions.
- The malicious code reads files available to the Agent, including resume source files, generated documents, tracker data, and environment variables.
- Depending on the runtime's network policy, the code may exfiltrate that informa ...[truncated 689 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin each dependency to a reviewed exact version, for example:
yaml python_packages: - python-docx==REVIEWED_VERSION - lxml==REVIEWED_VERSION -
Use a lock file or requirements file containing cryptographic hashes and install with hash enforcement, such as
pip install --require-hashes. -
Keep the top-level and
metadata.clawdbotdependency declarations synchronized so they cannot resolve different versions. -
Retrieve packages only from an explicitly configured, trusted package index; disable unintended extra indexes to reduce dependency-confusion exposure.
-
Install dependencies in an isolated virtual environment or container with minimal filesystem and network access.
-
Run dependency vulnerability and provenance checks before updating pinned versions.
-
Restrict the Agent process to only the resume, output, template, and tracker paths required for its declared functionality.
-
