T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Credential-Handling Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27–28 and 82–87
Vulnerability Type: Unpinned executable dependency with access to credentials and network transport
Risk Level: MediumComplete Code Snippet:
yaml openclaw: requires: bins: ["uno"] skills: ["uno-cli"]markdown 1. Install `uno-cli` (skipping if already installed): ```bash clawhub install uno-cli ``` On platforms that honour `metadata.openclaw.skills`, this dependency is installed automatically when this skill is installed.Technical Analysis
The skill depends on the executable
uno-clicompanion skill but does not pin it to a reviewed version, immutable digest, verified publisher identity, or cryptographic signature. Installation therefore resolves whichever release the dependency source currently supplies, including automatic installation on supported platforms.This dependency occupies a security-sensitive trust position. According to the skill documentation, it manages OAuth authentication, accesses the bearer credential stored at
~/.clawdchat/credentials.json, transports user prompts and reference-image URLs, and submits paid image-generation requests. Although the audited package does not directly open or transmit the credential file, its unpinned dependency is entrusted with those operations.This is a supply-chain weakness rather than evidence that the current dependency is malicious. If the package source, publisher account, name resolution, or a future dependency release were compromised, attacker-controlled code could execute with the permissions granted to
uno-cli.Attack Path
- An attacker compromises the
uno-clipublisher account or dependency repository, or causes the unqualified dependency name to resolve to a malicious release. - A user installs this skill, and the platform automatically installs
uno-cli, or the user follows `clawhub install uno-cli ...[truncated 1059 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
uno-clito a specifically audited version and, where supported, an immutable package digest. - Require cryptographic signature verification and validate the expected publisher identity before installation.
- Avoid automatic dependency installation when version and integrity enforcement are unavailable.
- Document the trusted package source and reject alternate or ambiguous registries.
- Apply least privilege to the companion process: restrict filesystem access to the required credential file and constrain network egress to the documented HTTPS gateway.
- Scope and rotate bearer credentials where supported, and provide clear revocation procedures.
- Preserve the existing explicit confirmation requirement for every paid submission or pre-authorized batch.
- Warn users that reference-image URLs may contain signed query credentials and recommend short-lived, narrowly scoped URLs without unrelated secrets.
- Pin
