T08 · Insecure Dependencies
- Location
install.sh:12- Finding
Unpinned Third-Party Dependencies Installed from Mutable Sources
- Content
View full analysis
Vulnerability Details
File Location:
install.sh, line 12
Vulnerability Type: Supply-chain exposure through unpinned dependencies
Risk Level: MediumVulnerable Code:
bash pip3 install chromadb sentence-transformers pyyamlTechnical Analysis
The installation script installs three third-party packages without exact version constraints, integrity hashes, a lockfile, or an explicitly trusted package index. Consequently, the code installed and executed can change between installations without any modification to this project.
Python package installation may execute package-controlled build or installation logic with the privileges of the user running the installer. The documented minimum dependency versions in
SKILL.mdare also not enforced by this command. This can result in the installation of incompatible, vulnerable, or compromised future releases.This finding does not establish that the named packages are currently malicious. The vulnerability is the absence of controls that ensure users receive the dependency versions reviewed and tested by the project.
Attack Path
- An attacker compromises an upstream package account, package release, distribution channel, or package-resolution environment.
- The attacker publishes or causes resolution to a malicious version of one of the unpinned dependencies.
- A user executes
install.sh. pip3resolves the mutable package name to the attacker-controlled release.- Malicious installation or runtime code executes with the privileges of the user who invoked the script.
Impact Assessment
Successful exploitation can execute arbitrary code under the installing user's account. That code could access files and credentials available to that user, alter the OpenClaw installation, tamper with stored agent memory, or establish further persistence. If the installer is run with elevated privileges, the impact could extend to system-level resou ...[truncated 60 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency to an exact, reviewed version.
- Generate and commit a reproducible lockfile containing transitive dependencies.
- Require cryptographic hashes during installation, such as through a hash-locked requirements file and
pip install --require-hashes. - Configure an explicit trusted package index rather than relying on ambient pip configuration.
- Install dependencies inside a dedicated virtual environment with least privilege.
- Add automated dependency vulnerability and provenance checks to the release process.
- Update the installation command to use the reviewed lockfile, for example:
bash python3 -m pip install --require-hashes -r requirements.lock
