T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned External Skill Installation Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–40
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: MediumVulnerable Code Snippet
markdown | `lbs-amap/personal-map` | [ClawHub](https://clawhub.ai/lbs-amap/personal-map) | Amap Web Service API wrapper / 高德 Web 服务 API 封装。安装命令:`openclaw skills install personal-map`。提供 `AMapPersonalMapClient` 类(import 路径 `scripts.amap_personal_map_client`),本仓库自身不含该脚本。 |text 1. personal-map skill installed? → No → 提示: "请先安装 personal-map skill,运行: openclaw skills install personal-map"The same unpinned command is reiterated at
SKILL.md:339.Technical Analysis
The Skill instructs users or agents to install an external dependency using the short, unversioned identifier
personal-map. Although the documentation identifies the expected project aslbs-amap/personal-map, the installation command does not include that namespace, a reviewed version, an immutable digest, or a signature verification step.Consequently, dependency resolution may retrieve a mutable future release or, depending on registry name-resolution behavior, an unintended package. This project contains no local implementation of
AMapPersonalMapClient, so the externally installed component supplies all executable behavior associated with API access, route processing, and QR-code generation.The dependency is expected to read
AMAP_API_KEYand perform network operations. A malicious or compromised release would therefore execute in a security-sensitive context.Attack Path
- An attacker compromises the mutable
personal-mappackage, publishes a malicious future release, or registers a package that wins ambiguous short-name resolution. - A user or agent follows the documented command:
bash openclaw skills install personal-map - The package manager installs the attacker-controlled dependency because no version, digest, or verified publisher identity is required ...[truncated 829 chars]
- An attacker compromises the mutable
- Remediation
View remediation
Remediation Suggestions
- Use the fully qualified package identity rather than the ambiguous short name.
- Pin the dependency to a reviewed version and, where supported, an immutable content digest.
- Verify the package publisher, registry signature, and expected checksum before installation.
- Document a known-good dependency version and a controlled upgrade-review process.
- Grant the dependency only the minimum filesystem, environment-variable, and network access necessary.
- Avoid exposing unrelated credentials to the process that loads the dependency.
- If the package manager cannot provide immutable pinning and authenticity verification, vendor and review the required implementation or use a trusted lockfile mechanism.
