T08 · Insecure Dependencies
- Location
QUICKSTART.md:5- Finding
Execution of Unpinned External Code and Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
QUICKSTART.md:5-22andSKILL.md:44-56
Vulnerability Type: Unverified external repository and unpinned third-party dependencies
Risk Level: HighVulnerable Code
bash ### 1. 克隆项目 ```bash git clone https://github.com/kk43994/claw-desktop-pet.git cd claw-desktop-pet2. 安装依赖
bash npm install pip install edge-tts3. 启动应用
bash npm starttext The same installation sequence is also documented in `SKILL.md:44-56`. ### Technical Analysis The supplied artifact contains documentation rather than the advertised application source. Its installation procedure clones a mutable remote repository without selecting or verifying a reviewed commit, tag, release signature, or cryptographic checksum. It then installs unpinned npm and Python dependencies before executing the downloaded application. Because the remote source, package manifests, lockfiles, lifecycle scripts, and dependency contents are absent from the audited artifact, their integrity and behavior cannot be validated. An npm installation may execute package lifecycle scripts, while `npm start` directly executes code obtained from the mutable repository. The unpinned `edge-tts` installation also allows a later package version to be selected without review. This creates a supply-chain trust boundary in which the code ultimately executed by the user may differ from the content that was reviewed. ### Attack Path 1. An attacker compromises the referenced repository, its maintainer account, an npm dependency, or the selected Python package release. 2. The attacker inserts malicious application code or an installation lifecycle script into the mutable source or dependency chain. 3. A user follows the documented commands and clones the current repository state. 4. `npm install` or `pip install edge-tts` retrieves the attacker-controlled component. 5. An npm lifecycle script may execute during installation, or the malicious code ...[truncated 778 chars]- Remediation
View remediation
Remediation Suggestions
- Include the complete application source and dependency manifests in the reviewed skill artifact so that runtime behavior can be audited.
- Pin the external repository to a specific reviewed commit hash rather than cloning a mutable default branch.
- Distribute signed releases and require users to verify the release signature or a checksum obtained through a trusted channel.
- Commit an npm lockfile with integrity metadata and replace
npm installwithnpm cito enforce the reviewed dependency graph. - Pin
edge-ttsto an explicitly reviewed version and use a Python requirements file containing cryptographic hashes, installed withpip install --require-hashes. - Review npm lifecycle scripts and, where compatible with the application, install dependencies with scripts disabled before explicitly running only trusted build steps.
- Add automated dependency scanning, provenance verification, and maintainer-account protections to the release process.
- Run installation and execution with least privilege in an isolated environment; users should not run these commands as an administrator.
