T08 · Insecure Dependencies
- Location
SKILL.md:92- Finding
Unpinned Third-Party Packages Installed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 92–98
Vulnerability Type: Unpinned runtime dependencies
Risk Level: Mediumbash # Check if venv exists, create if not if [ ! -d ~/openclaw_python_venv ]; then python3 -m venv ~/openclaw_python_venv source ~/openclaw_python_venv/bin/activate pip install qrcode pillow else source ~/openclaw_python_venv/bin/activate fiTechnical Analysis
The Skill instructs the agent to install
qrcodeandpillowdynamically from the package index without pinning versions or verifying package hashes. Consequently, the installed artifacts are mutable and may differ from those available when the Skill was reviewed.This creates a software supply-chain risk. If a package release, distribution account, package-index response, or transitive dependency is compromised, malicious installation or runtime code could execute under the agent user's account. The package names do not appear to be typosquatted, and the audited files contain no evidence that the author intentionally introduced malicious packages; the finding concerns missing dependency integrity controls.
Attack Path
- An attacker compromises a future release or distribution channel for
qrcode,pillow, or one of their resolved dependencies. - A user explicitly requests QR-code generation.
- If
~/openclaw_python_venvdoes not exist, the agent creates it and runspip install qrcode pillow. pipresolves and downloads the currently available, unverified package artifacts.- Malicious package installation logic can execute during installation; malicious library code can also execute when the subsequent Python QR-generation script imports the package.
- The payload runs with the permissions of the account executing the Skill.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the agent user's privileges. Depending on that account' ...[truncated 445 chars]
- An attacker compromises a future release or distribution channel for
- Remediation
View remediation
Remediation Suggestions
- Pin every direct and transitive dependency to a reviewed version in a committed lock or requirements file.
- Record cryptographic hashes and install with hash enforcement, for example:
bash python3 -m pip install --require-hashes -r requirements.txt - Use an approved package repository or internally mirrored artifact source with provenance and integrity controls.
- Prefer dependencies preinstalled and reviewed by the runtime instead of downloading packages during Skill execution.
- Build the virtual environment during a controlled deployment phase rather than in response to a user request.
- Run QR generation in a restricted environment with minimal filesystem and network access.
- Regularly scan and update the locked dependencies through a documented review process.
