T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Third-Party Dependency Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6-9
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
yaml metadata: openclaw: emoji: 🍜 requires: bins: ["python"] pip: ["requests"]Technical Analysis
The Skill declares
requestsas an installation requirement without specifying a reviewed version, dependency lockfile, package hash, or trusted package-index restriction. Consequently, dependency resolution can select a different package release over time, making the installed code differ from the version originally audited.Although the declared package name is legitimate and no malicious dependency is included in the repository, this configuration exposes the installation process to mutable upstream releases and package-index compromise. Python packages can execute code during installation and subsequently when imported by
baidu_map_client.py. A malicious dependency release or compromised package source could therefore introduce code that was not present during this audit.Attack Path
- An attacker compromises the configured Python package index, an upstream dependency release, or the dependency distribution process.
- The attacker publishes or serves a malicious version of
requestsor one of its transitive dependencies. - The Skill is installed or provisioned in a new environment using the unpinned
pip: ["requests"]requirement. - The package resolver selects the attacker-controlled release because no version or integrity hash is enforced.
- Malicious package code executes during installation or when
requestsis imported bybaidu_map_client.py. - The malicious code operates with the permissions of the account running the Skill installation or Agent process.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the Skill installer or Agent r ...[truncated 385 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
requeststo a specifically reviewed version rather than allowing unconstrained resolution, for example:yaml pip: ["requests==2.32.5"] - Use a dependency lockfile that records all transitive dependency versions.
- Require cryptographic hashes for downloaded distributions, such as through a hash-locked requirements file and
pip install --require-hashes. - Install dependencies only from an approved HTTPS package index, and disable untrusted supplemental indexes.
- Periodically review and deliberately update pinned versions after vulnerability and provenance checks.
- Perform installation in an isolated, least-privileged environment without unnecessary credentials or access to sensitive host files.
- Pin
