T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party CLI Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:4,17-20
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumThe skill directs users to install mutable versions of a third-party executable globally. The npm command has no version constraint, and the Go command explicitly selects
@latest.yaml metadata: {"openclaw": {"emoji": "📄", "requires": {"bins": ["mineru-open-api"], "env": ["MINERU_TOKEN"]}, "primaryEnv": "MINERU_TOKEN", "install": [{"id": "npm", "kind": "node", "package": "mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via npm"}, {"id": "go", "kind": "go", "package": "github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via go install", "os": ["darwin", "linux"]}]}}bash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
These commands retrieve and execute whichever package release is current at installation time, rather than a version reviewed alongside the skill. Consequently, the effective executable can change after this skill has been audited.
The npm installation is global and may run package lifecycle scripts during installation. The Go command also builds and installs code from a mutable upstream release selected through
@latest. The installed CLI is subsequently expected to receive access to theMINERU_TOKENenvironment variable and to process user-selected local documents. If the upstream package, publisher account, repository, release process, or transitive dependency were compromised, a malicious release could execute with the installing user's privileges.No evidence establishes that the current upstream packages are malicious. The finding concerns the unsafe, unpinned dependency installation mechanism and the resulting supply-chain exposure.
Attack Path
- An attack ...[truncated 1363 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to a specific, reviewed release rather than relying on an implicit current npm version or Go
@latest. - For npm, use an exact version such as
mineru-open-api@X.Y.Z, commit and verify the appropriate lockfile where applicable, and validate package integrity against a trusted checksum or registry integrity value. - For Go, replace
@latestwith a reviewed semantic version or immutable commit identifier and verify it through the expected Go module checksum mechanism. - Prefer a project-local or isolated installation over a global installation to reduce the package's reach and simplify removal.
- Review transitive dependencies and package lifecycle scripts before approving upgrades.
- Document that local files and credentials are exposed to the third-party CLI and potentially to its remote service.
- Provide upgrade guidance that requires security review and checksum verification before changing the pinned version.
- Run the converter with minimal filesystem permissions and a narrowly scoped, revocable token; avoid invoking installation or conversion commands with elevated privileges.
- Pin both installation methods to a specific, reviewed release rather than relying on an implicit current npm version or Go
