T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Third-Party CLI Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9-18
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumThe skill instructs users to install
mineru-open-apifrom mutable upstream sources without specifying a reviewed version, checksum, lockfile, or signature.yaml metadata: {"openclaw": {"emoji": "📄", "requires": {"bins": ["mineru-open-api"], "env": ["MINERU_TOKEN"]}, "primaryEnv": "MINERU_TOKEN", "install": [{"id": "npm", "kind": "node", "package": "mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via npm"}, {"id": "go", "kind": "go", "package": "github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api", "bins": ["mineru-open-api"], "label": "Install via go install", "os": ["darwin", "linux"]}]}}bash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The npm installation command resolves to the registry's current package version, while the Go command explicitly resolves the mutable
@latestversion. Consequently, the code installed by following these instructions can change after this skill has been reviewed.The project does not provide an exact dependency version, cryptographic checksum, signed-release verification procedure, lockfile, or vendored source. The npm command also installs the package globally, exposing its executable system-wide and potentially executing package lifecycle scripts during installation. The Go command retrieves and compiles upstream source whose content depends on the version selected as
latest.This does not prove that the current upstream package is malicious. It creates a supply-chain exposure in which compromise of the package registry, upstream repository, maintainer account, or a future release could cause users to install attacker-controlled code.
Attack Path
- An attacker compromises the upstream package, its re ...[truncated 1623 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to exact, reviewed versions rather than relying on the current registry release or
@latest:bash npm install -g mineru-open-api@<reviewed-version> go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@v<reviewed-version> - Publish expected cryptographic checksums or require verification of signed upstream releases before installation.
- Record the reviewed package version and source commit in the skill metadata.
- Add an npm lockfile or equivalent reproducible dependency manifest where the deployment model permits it.
- Prefer a local, isolated installation over a global npm installation, and execute the CLI in a sandbox or container with access limited to the required presentation and output directory.
- Do not expose unrelated secrets to the CLI process. Supply
MINERU_TOKENonly when full extraction requires it and use a narrowly scoped, revocable token. - Review package lifecycle scripts and transitive dependencies before approving a new version.
- Establish an update process that performs source review, integrity verification, and security testing before changing the pinned version.
- Pin both installation methods to exact, reviewed versions rather than relying on the current registry release or
