T08 · Insecure Dependencies
- Location
SKILL.md:51- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 51-54
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Mediummarkdown ## Requirements - faster-whisper: `pip install faster-whisper` - TTS already configured in OpenClawTechnical Analysis
The documented installation command retrieves
faster-whisperwithout pinning an audited version, verifying package hashes, using a dependency lockfile, or restricting resolution to an explicitly trusted package index. Its transitive dependencies are similarly unconstrained.Consequently, the code installed by users may differ from the code assessed during this audit. If a future package release, transitive dependency, build dependency, or package-resolution source is compromised, installation or subsequent import and execution could run attacker-controlled code with the privileges of the user operating the agent.
No evidence indicates that the currently referenced package is malicious. The vulnerability is the mutable and insufficiently verified dependency acquisition process.
Attack Path
- An attacker compromises a future release, transitive dependency, build dependency, or package-resolution source used by pip.
- A user follows the documented
pip install faster-whisperinstruction. - Pip resolves and downloads the compromised package because no approved version or cryptographic hash is enforced.
- Malicious code executes during a source-package build, dependency installation, package import, or voice transcription.
- The malicious code operates with the permissions and data access available to the user running the installation or agent.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the attacker could access local files, voice-message contents, Telegram-related data available to the process, con ...[truncated 182 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable installation command with an exact, reviewed version pin.
- Maintain a lockfile that fixes all transitive and build dependencies to reviewed versions.
- Record and enforce cryptographic hashes, such as through a generated requirements file installed with
pip install --require-hashes -r requirements.txt. - Configure pip to use an explicitly trusted package index and disable unintended additional indexes.
- Prefer prebuilt, verified wheels where appropriate and avoid unreviewed source builds.
- Scan locked dependencies for known vulnerabilities and review dependency changes before updating the lockfile.
- Perform installation and transcription under a dedicated, least-privileged account or isolated environment with limited access to credentials and sensitive files.
