T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Dependencies Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:4
Vulnerability Type: Unpinned third-party dependencies
Risk Level: MediumVulnerable Code:
yaml metadata: {"openclaw":{"emoji":"🔬","requires":{"bins":["python"]},"install":[{"id":"pip","kind":"uv","packages":["fastapi","uvicorn","pydantic","pyyaml"]}]}}Technical Analysis
The installation metadata requests
fastapi,uvicorn,pydantic, andpyyamlwithout exact version constraints, integrity hashes, or a committed lockfile. Consequently, identical installations performed at different times may resolve to different package versions.The listed package names do not appear to be typosquatted or intentionally malicious. Nevertheless, unconstrained resolution means that a compromised upstream release, malicious registry response, or unexpectedly incompatible future version could enter the execution environment without a corresponding change to the reviewed Skill source.
These dependencies are imported by the application and therefore execute within the server process. For example,
scopecheck/app.pyimports FastAPI, whilescopecheck/models.pyimports Pydantic andscopecheck/extractors.pyimports PyYAML.Attack Path
- An operator installs the Skill using its declared
uvinstallation configuration. - The resolver queries the configured package registry for the current versions of the four unpinned packages and their transitive dependencies.
- A compromised or otherwise unsafe release is selected because no reviewed version or artifact hash is enforced.
- The package is downloaded and installed.
- Attacker-controlled code may execute through package installation behavior, module import, or application startup.
- The code runs with the permissions and accessible resources of the account or container hosting the Skill.
This is a supply-chain exposure rather than evidence that any dependency currently named by the project is ...[truncated 656 chars]
- An operator installs the Skill using its declared
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, security-reviewed version.
- Generate and commit a lockfile that also fixes all transitive dependency versions.
- Require cryptographic hashes for downloaded artifacts where the installation system supports them.
- Resolve packages only from a trusted, authenticated registry or an internally controlled mirror.
- Add automated dependency vulnerability and provenance scanning to the release process.
- Review and deliberately update the lockfile on a controlled schedule rather than resolving unrestricted current versions during deployment.
- Run installation and the API service as an unprivileged user in an isolated environment with minimal filesystem, environment-variable, and network access.
