T08 · Insecure Dependencies
- Location
MEMORY-STACK.md:50- Finding
Unpinned Global Installation of Third-Party Memory Components
- Content
View full analysis
Vulnerability Details
File Location:
MEMORY-STACK.md:50-57andMEMORY-STACK.md:148-152
Vulnerability Type: Supply-chain exposure through mutable, globally installed dependencies
Risk Level: MediumVulnerable Code
bash ### Installation # Install via bun (recommended) bun install -g @tobilu/qmd # Or via npm npm install -g @tobilu/qmdbash ### Installation # Install via OpenClaw plugin system openclaw plugins install @martian-engineering/lossless-clawEquivalent unpinned commands also appear in
MEMORY-STACK.zh-CN.md:50-57andMEMORY-STACK.zh-CN.md:148-152.Technical Analysis
The installation instructions retrieve mutable package versions without specifying an audited version, lockfile, integrity hash, or immutable source revision. The
qmdpackage is installed globally, while LosslessClaw is installed as an OpenClaw plugin.These components operate on security-sensitive data:
qmdindexes files undermemory/andblackboard/.- LosslessClaw processes historical conversations and stores summaries in
~/.openclaw/lcm.db. - The plugin executes within the OpenClaw environment and therefore inherits the permissions granted to that environment.
The project does not itself contain a malicious dependency. The vulnerability is that following the documented commands resolves whatever package release is current at installation time. A registry compromise, maintainer-account compromise, or malicious future release could therefore change the code executed after this Skill was reviewed.
Attack Path
- An attacker compromises the registry package, its publisher account, or the upstream release process.
- The attacker publishes a malicious release under the legitimate package name.
- A user follows the documented unversioned installation command.
- The package manager resolves and installs the attacker-controlled release.
- The malicious package ex ...[truncated 1083 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every package to a reviewed exact version, for example
package@x.y.z. - Publish expected package integrity hashes or use a lockfile that records integrity metadata.
- Pin plugin installation to an immutable release or commit when the plugin system supports it.
- Avoid global package installation where possible. Run the indexer in a dedicated environment with access only to explicitly selected directories.
- Document the exact filesystem and network permissions required by each component.
- Run third-party plugins under a restricted service account or sandbox without access to unrelated OpenClaw configuration and credentials.
- Establish an upgrade-review procedure rather than automatically consuming the latest package release.
- Verify package ownership, provenance, signatures, and registry namespace before installation.
- Pin every package to a reviewed exact version, for example
