T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Dependencies Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable code:
yaml metadata: {"openclaw":{"emoji":"🔄","requires":{"bins":["python"]},"install":[{"id":"pip","kind":"uv","packages":["fastapi","uvicorn","pydantic","pyyaml"]}]}}Technical Analysis
The installation metadata requests
fastapi,uvicorn,pydantic, andpyyamlwithout exact version constraints or integrity hashes. Consequently, dependency resolution can produce different installations over time and may select a compromised, malicious, or incompatible future release.The package names appear to correspond to legitimate dependencies, and the reviewed project contains no evidence that they are currently malicious. The risk arises because the dependency source and resulting artifacts are not cryptographically fixed to versions reviewed by the project maintainers.
Attack Path
- An attacker compromises the publishing account, distribution infrastructure, or a transitive dependency associated with one of the declared packages.
- The attacker publishes a malicious release under a dependency name used by the installation metadata.
- A user installs the skill after that release becomes eligible for unconstrained resolution.
- The
uv-based installer resolves and downloads the malicious or compromised package. - Malicious behavior executes during package installation, module import, or server startup, subject to the behavior of the compromised package and the privileges of the installation process.
This exploitation path depends on an upstream supply-chain compromise; no direct remote code retrieval or deliberately malicious dependency was identified in the project itself.
Impact Assessment
A compromised dependency could execute code with the privileges of the account installing or running FormatGate. Depending on that account's permissions ...[truncated 346 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a reviewed, exact version rather than using unconstrained package names.
- Generate and commit a lockfile that also fixes all transitive dependency versions.
- Require cryptographic hashes for downloaded distributions where the installation workflow supports hash verification.
- Configure installation to use an explicitly trusted package index and disable unintended fallback indexes to reduce dependency-confusion exposure.
- Regularly scan pinned dependencies for known vulnerabilities and update them through a controlled review process.
- Perform installation and runtime execution under a dedicated, least-privileged account or isolated environment.
- Rebuild and test the locked environment reproducibly before publishing updated dependency versions.
