T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
- Remediation
View remediation
openclaw init` - `pip install xclaw02==` 2. Verify package integrity with registry lockfiles, cryptographic hashes, signed provenance, or an equivalent trusted mechanism. 3. Avoid using `npx` in a mode that automatically downloads and executes an unspecified latest release. 4. Include the relevant implementation source in the review scope or link the Skill to an immutable source revision. 5. Audit direct and transitive dependencies and enable registry provenance and publisher-account protections. 6. Run setup and wallet operations in an isolated, least-privileged environment with access only to required files and network destinations. 7. Keep wallet funds limited to the amount required for the immediate task and enforce transaction limits outside the downloaded package where possible. 8. Separate wallet signing from the network-facing client so the package cannot directly read or export raw private keys. ]]>
