T08 · Insecure Dependencies
- Location
SKILL.md:125- Finding
Unpinned Third-Party Plugin Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 125 and 158–159
Vulnerability Type: Unpinned and externally hosted third-party dependencies
Risk Level: MediumVulnerable Code Snippets
SKILL.md, line 125:bash npm install mnemo-openclawSKILL.md, lines 158–159:text | **Claude Code** | `/plugin marketplace add qiffang/mnemos` → `/plugin install mnemo-memory@mnemos` | | **OpenCode** | `"plugin": ["mnemo-opencode"]` in `opencode.json` |Technical Analysis
The installation instructions reference mutable npm packages and a remote plugin marketplace without pinning an exact package version, immutable commit hash, or integrity digest. Consequently, the code installed by a user may differ from the code that was available when this skill documentation was reviewed.
The project contains only
SKILL.md; it does not include the source code, lockfiles, checksums, signatures, or software bill of materials for the referenced plugins. The actual runtime behavior ofmnemo-openclaw,mnemo-opencode, andmnemo-memory@mnemostherefore cannot be verified from this artifact.This creates a supply-chain trust boundary. If a package publisher account, npm package, marketplace repository, release process, or dependency is compromised, a subsequent installation could retrieve attacker-controlled plugin code. Because the advertised plugins handle cloud-persistent agent memory and TiDB credentials, compromise could expose particularly sensitive data.
The documented network communication with TiDB Cloud is declared and necessary for the skill's cloud-persistence functionality. No hidden network destination or confirmed credential-exfiltration logic was found in
SKILL.md; the risk arises from installing unaudited, mutable external implementations.Attack Path
- An attacker compromises a referenced package, publisher account, marketplace repository, or an upstream dependency.
...[truncated 1348 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every npm plugin to an exact reviewed version, for example:
bash npm install --save-exact mnemo-openclaw@<reviewed-version> - Pin marketplace installations to an immutable release tag or commit hash rather than a mutable repository or channel.
- Publish and verify cryptographic integrity hashes or signed release attestations before installation.
- Include lockfiles and a software bill of materials so direct and transitive dependencies can be reproduced and audited.
- Make the referenced plugin source available alongside the skill or link each documented release to the exact audited source revision.
- Use automated dependency scanning, provenance verification, and publisher-account protections such as phishing-resistant multi-factor authentication.
- Run plugins in a restricted sandbox with only the filesystem, network destinations, and tools required for memory operations.
- Use a dedicated least-privilege database account limited to the required memory schema and operations. Do not use administrative TiDB credentials.
- Restrict outbound traffic to explicitly approved TiDB or self-hosted server endpoints.
- Warn users not to store secrets in agent memory and document credential rotation and revocation procedures for suspected package compromise.
- Pin every npm plugin to an exact reviewed version, for example:
