T08 · Insecure Dependencies
- Location
README.md:143- Finding
Unpinned Third-Party Dependencies and Mutable Package Installation
- Content
View full analysis
=0.6.21 lxml>=4.9.0 ``` ### Technical Analysis The installation instructions do not select immutable, previously reviewed package artifacts. The unversioned `pip install` command retrieves whichever compatible releases are current at installation time. The requirements files use lower bounds rather than exact versions, allowing future versions of both packages to be installed without review. The command `npx clawhub@latest` is more explicitly mutable: the `latest` distribution tag can resolve to a different package version after this project has been audited. Package-manager installation and execution therefore place trust in future registry content, publisher accounts, transitive dependencies, and package lifecycle behavior. No evidence shows that the currently named packages are malicious. The vulnerability is the lack of reproducibility and integrity enforcement, which allows the effective code installed or executed by users to change after review. ### Attack Path 1. An attacker compromises a dependency publisher, package registry, release workflow, or transitive dependency. 2. The attacker publishes a malicious release that still satisfies `python-pptx>=0.6.21` or `lxml>=4.9.0`, or changes the package resolved through the `latest` ClawHub ta ...[truncated 1164 chars]- Remediation
View remediation
lxml== ``` 2. Generate and commit a lock file containing all transitive dependencies. 3. Require artifact hashes during installation. For pip, maintain a hash-locked requirements file and install it with: ```bash python -m pip install --require-hashes -r requirements.lock ``` 4. Replace `npx clawhub@latest` with a specific reviewed version: ```bash npx clawhub@ install mck-ppt-design ``` 5. Configure package managers to use explicitly trusted registries and avoid unintended fallback registries. 6. Run dependency installation in an isolated virtual environment or container under a non-privileged account. 7. Add automated dependency scanning and a controlled update process. Review source changes, transitive dependencies, package ownership, and checksums before updating pinned versions. 8. Keep the installation commands in `README.md`, `SKILL.md`, and both requirements files synchronized so that none of the documented paths bypass the hardened dependency policy. ]]>
