T08 · Insecure Dependencies
- Location
install.sh:19- Finding
Unpinned Third-Party Dependencies Permit Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
install.sh:19-24;README.md:24-27;docs/quick_start_en.md:18-21;docs/zh-CN/ChromaDB插件_快速安装指南.md:30-33
Vulnerability Type: Unrestricted dependency installation
Risk Level: MediumVulnerable Code
install.sh:19-24:bash echo "[*] Installing dependencies..." pip3 install chromadb sentence-transformers pyyaml if [ $? -ne 0 ]; then echo "[!] Dependency installation failed" exit 1 fiREADME.md:24-27:bash ### Manual install ```bash pip install chromadb openclaw-extension-chromadbtext `docs/quick_start_en.md:18-21`: ```bash ### Manual install ```bash pip install chromadb sentence-transformers openclaw-extension-chromadbtext ### Technical Analysis The installer retrieves and installs the latest available versions of `chromadb`, `sentence-transformers`, and `pyyaml` without a lock file, version constraints, or integrity hashes. Python package installation can execute package-controlled build and installation code with the privileges of the invoking user. The manual installation documentation additionally instructs users to install `openclaw-extension-chromadb`. That package is not part of the audited project and is not listed among the dependencies in `SKILL.md`. Its necessity, version, provenance, and integrity are therefore not established by the audited source. This does not prove that any named package is currently malicious. It creates a supply-chain exposure in which the code executed during future installations can differ from the code that was reviewed. ### Attack Path 1. An attacker compromises a dependency release, its maintainer account, or the package-index delivery path, or publishes a malicious package under the additional documented package name. 2. A user executes `install.sh` or follows one of the manual `pip install` instructions. 3. `pip` resolves the dependency to the attacker- ...[truncated 775 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every direct and transitive dependency to a reviewed version using a lock file.
- Require package hashes, for example through
pip install --require-hashes -r requirements.txt. - Install dependencies inside a dedicated virtual environment rather than the user's global Python environment.
- Use a trusted, explicitly configured package index and retain reviewed package artifacts where practical.
- Remove
openclaw-extension-chromadbfrom the documentation unless it is necessary and its ownership, package source, exact version, and integrity are verified. - Make the installer invoke the selected interpreter consistently, such as
python3 -m pip, to avoid installing into an unintended environment. - Add dependency scanning and lock-file update review to the release process.
