T08 · Insecure Dependencies
- Location
scripts/run.py:10- Finding
Unverified External Python Module Loaded Through Runtime Path Manipulation
- Content
View full analysis
Path: """ 将 cloud 客户端目录加入 sys.path。 - ClawHub zip:scripts/ 内已有 yufluent_api.py(package-skill 注入) - Monorepo:回退 skills/_shared/ """ scripts_dir = Path(script_file).resolve().parent skills_shared = scripts_dir.parent.parent / "_shared" for candidate in (scripts_dir, skills_shared, _SHARED_DIR): if candidate.is_dir() and (candidate / "yufluent_api.py").is_file(): path = str(candidate) if path not in sys.path: sys.path.insert(0, path) return candidate raise ImportError( "cloud client not found: expected scripts/yufluent_api.py (ClawHub) " "or skills/_shared/yufluent_api.py (monorepo)" ) ``` ### Technical Analysis The project does not contain `yufluent_api.py`, even though `scripts/run.py` imports and executes its `run_skill` function. The loader searches the local `scripts` directory and an external sibling `_shared` directory, prepends a matching directory to `sys.path`, and then imports the module by its unqualified name. Consequently, the central network client is outside the reviewed artifact. Its endpoi ...[truncated 2031 chars]- Remediation
View remediation
