T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–12
Vulnerability Type: Unpinned third-party package dependency
Risk Level: MediumVulnerable Code
yaml install: - kind: uv package: youam bins: - uamTechnical Analysis
The skill instructs the environment to install the third-party
youampackage throughuvwithout specifying an exact version or an integrity hash. Consequently, installation can resolve mutable package-index content that was not included in this audit.If the package publisher account, distribution infrastructure, or configured package index is compromised, a malicious release could be selected during installation. Package installation, importing
uam.plugin.openclaw, or running the installeduamexecutable could then execute dependency-controlled code with the privileges of the agent process.Attack Path
- An attacker compromises the upstream
youampublishing account, package repository, or package-distribution infrastructure. - The attacker publishes or substitutes a malicious package release.
- The skill installation process resolves the unpinned
youamdependency to that release. - Malicious code runs during installation, when the
uamcommand is invoked, or when the plugin is imported. - The malicious package accesses resources available to the agent process or alters the behavior of the messaging integration.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the process installing or using the dependency. Depending on the host environment, this could expose local files, generated identity and encryption-key material, contact information, or message contents. It could also enable unauthorized outbound network activity or modification of files accessible to the agent.
The reviewed project contains only
SKILL.md; no bundled executable code was present. Therefore, the fi ...[truncated 116 chars]- An attacker compromises the upstream
- Remediation
View remediation
Remediation Suggestions
- Pin
youamto a specific version that has undergone security review. - Require and verify package integrity hashes or trusted cryptographic signatures.
- Configure an explicit, trusted package index rather than relying on implicit resolver configuration.
- Lock and audit all transitive dependencies.
- Re-review the resolved package contents whenever the pinned version is updated.
- Run installation and messaging components with least privilege and restrict access to unrelated files and credentials.
- Apply appropriate outbound-network controls so the package can communicate only with approved endpoints.
- Pin
