T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Mutable Third-Party Dependency Sources
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:4;references/install.md:7-10;references/install.md:51-55
Vulnerability Type: Supply-chain risk through unpinned third-party dependencies
Risk Level: MediumVulnerable Code
SKILL.md:4:yaml metadata: {"openclaw":{"homepage":"https://github.com/lastarla/bookkeeping-agent","requires":{"bins":["bookkeeping"]},"install":[{"id":"brew","kind":"brew","formula":"lastarla/tap/bookkeeping-tool","bins":["bookkeeping"],"label":"Install bookkeeping (Homebrew, macOS)"},{"id":"pipx","kind":"pipx","package":"git+https://github.com/lastarla/bookkeeping-tool.git","bins":["bookkeeping"],"label":"Install bookkeeping (pipx from GitHub)"}]}}references/install.md:7-10:bash brew install lastarla/tap/bookkeeping-toolreferences/install.md:51-55:text 如果上下文里没有本地路径、只有 Feishu 附件引用,再额外安装并启用 `@angli/openclaw-message-attachments` 作为下载 fallback。 推荐链路是: 1. 优先使用 OpenClaw 已落盘的本地 inbound 文件 2. 如果没有本地路径,再调用附件下载插件 3. 使用返回的本地路径执行 `bookkeeping import <file> --json`Technical Analysis
The Skill recommends installing the
bookkeepingexecutable from a custom Homebrew tap or directly from a mutable GitHub repository. The Git dependency does not specify an immutable commit hash or release tag. The optional attachment plugin is also identified without a fixed version, checksum, or signature-verification procedure.These mutable dependency references cause the code ultimately installed or loaded by users to be determined by upstream state at installation time rather than by the reviewed Skill package. If an upstream repository, package publication account, Homebrew tap, plugin release, or maintainer account is compromised, malicious code could be distributed without any modification to this repository.
This finding does not establish that the named upstream projects are currently malicious. It identifies the absence of controls that bind ...[truncated 1552 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the pipx Git dependency to an immutable, reviewed commit:
text git+https://github.com/lastarla/bookkeeping-tool.git@<full-commit-hash> - Prefer signed, versioned releases over installation from a repository's mutable default branch.
- Pin the Homebrew formula to a reviewed version where supported, and ensure the formula verifies the downloaded artifact with a cryptographic SHA-256 checksum.
- Specify an exact reviewed version of
@angli/openclaw-message-attachmentsrather than relying on the latest available release. - Verify release signatures, checksums, repository ownership, and package provenance before recommending updates.
- Use automated dependency monitoring, but require security review before advancing pinned versions.
- Run the CLI and attachment plugin with least privilege, restricting access to unrelated files, credentials, and network destinations where the execution environment permits.
- Pin the pipx Git dependency to an immutable, reviewed commit:
