T08 · Insecure Dependencies
- Location
SKILL.md:53- Finding
Execution of an Unaudited External Publishing Script with Unpinned Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 53–117
Vulnerability Type: External executable and unpinned runtime dependencies
Risk Level: MediumVulnerable Code
bash node {baseDir}/scripts/xhs_publish.cjs check-loginbash node {baseDir}/scripts/xhs_publish.cjs loginbash node {baseDir}/scripts/xhs_publish.cjs publish content.jsonbash node {baseDir}/scripts/xhs_publish.cjs get-note <note-ID>The documentation also permits loading the script from this external workspace location:
text ~/.openclaw/workspace-xiaohongshu-publisher/scripts/xhs_publish.cjsRuntime dependencies are installed through unpinned commands:
bash npm install playwright npx playwright install chromiumTechnical Analysis
The audited project contains only
SKILL.md; it does not include the referencedscripts/xhs_publish.cjsimplementation, a package manifest, or a dependency lockfile. Consequently, the security-sensitive implementation responsible for browser automation, authentication-state handling, publishing, and data retrieval cannot be verified as part of this package.The documented fallback location is outside the audited Skill directory. Trusting an executable from a separately deployed workspace creates a mutable trust boundary: that file may be replaced or modified independently after this Skill is reviewed.
Playwright is also installed without an exact version or committed lockfile. Dependency resolution can therefore change over time. The npm installation process may execute package lifecycle scripts, while the browser installation command retrieves additional components. This exposes the workflow to package-registry compromise, dependency substitution, or an unexpected future dependency version.
Attack Path
- An attacker gains the ability to modify the separately deployed
xhs_publish.cjsfile, influence the path rep ...[truncated 1521 chars]
- An attacker gains the ability to modify the separately deployed
- Remediation
View remediation
Remediation Suggestions
- Include
scripts/xhs_publish.cjsin the Skill package so its browser actions, network destinations, input handling, and authentication-state management can be audited. - Do not silently fall back to an executable outside the Skill directory. Resolve the script from a canonical package-relative path and reject path traversal, symbolic-link redirection, and unexpected external locations.
- If an external deployment is unavoidable, pin the approved script by a cryptographic digest or signed release and verify it immediately before every execution.
- Add a package manifest and committed lockfile containing exact dependency versions and integrity metadata.
- Replace ad hoc installation with a reproducible command such as
npm ciagainst the reviewed lockfile. - Review all dependency lifecycle scripts. Where compatible with the deployment model, install with lifecycle scripts disabled and perform any required browser setup through a separately verified procedure.
- Pin and verify the expected Playwright and Chromium artifacts rather than accepting whichever versions are current at installation time.
- Run the publishing automation under a dedicated, least-privileged operating-system account or sandbox. Restrict filesystem access and outbound network access to the minimum required destinations.
- Preserve the existing explicit publication confirmations, and display the final title, body, tags, image paths, target account, and destination immediately before submission.
- Include
