T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Git Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Unpinned dependency from a mutable Git repository
Risk Level: MediumComplete Code Snippet:
yaml metadata: { "openclaw": { "homepage": "https://github.com/malphas-gh/clawpm", "requires": { "bins": ["clawpm"] }, "emoji": "📋", "install": [{ "id": "uv", "kind": "uv", "package": "git+https://github.com/malphas-gh/clawpm", "bins": ["clawpm"], "label": "Install clawpm (uv)" }] } }Technical Analysis
The installation configuration directs
uvto installclawpmfrom a Git repository without specifying an immutable commit hash, signed tag, or fixed release version. Consequently, installation resolves the repository's mutable default branch at install time. The code installed in the future may therefore differ from the code that was originally reviewed.The audited project contains only
SKILL.md; it does not include the dependency's implementation. The external executable and its installation behavior could not be verified from this artifact. This is a supply-chain weakness rather than evidence that the current upstream repository is malicious.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or another mechanism capable of modifying its default branch.
- The attacker adds malicious package installation logic or runtime code to the repository.
- A user or agent installs the Skill dependency using the declared
git+https://github.com/malphas-gh/clawpmsource. uvresolves and retrieves the attacker-modified default branch because no immutable revision is pinned.- Malicious code executes during package installation or when the installed
clawpmexecutable is invoked.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the account installing or running
clawpm. Depending on that account's permissions, the payload could read ...[truncated 406 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the Git dependency to a reviewed immutable commit hash rather than the mutable default branch.
- Prefer a fixed, trusted registry release with an exact version and integrity hash where feasible.
- Verify release signatures, provenance attestations, or checksums before installation.
- Adopt a lockfile or equivalent dependency-resolution control to make installations reproducible.
- Review the pinned upstream source, including build and installation hooks, before approving it.
- Use automated dependency monitoring and require security review before changing the pinned revision.
- Run installation and the resulting CLI with least privilege in an isolated environment where practical.
