T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:5
Vulnerability Type: Unpinned package dependency from an external package registry
Risk Level: MediumVulnerable Code Snippet:
json metadata: {"clawdbot":{"emoji":"📄","requires":{"bins":["nano-pdf"]},"install":[{"id":"uv","kind":"uv","package":"nano-pdf","bins":["nano-pdf"],"label":"Install nano-pdf (uv)"}]}}Technical Analysis
The installation metadata requests the
nano-pdfpackage by name without specifying an exact version or an integrity hash. Consequently, the dependency resolver may install whichever release is selected from the configured package registry at installation time rather than a release whose contents were reviewed with this Skill.Python package installation may execute package-controlled build or installation logic. If the package registry account, distribution process, package source, or configured package index is compromised, a malicious release could execute code during installation or when the
nano-pdfexecutable is invoked.The audited project does not bundle malicious package code, and the review found no evidence that the current
nano-pdfdistribution is malicious. The issue is the mutable and unverifiable dependency boundary.Attack Path
- An attacker compromises the upstream package publication process, registry account, or package source used by the resolver.
- The attacker publishes a malicious or modified
nano-pdfrelease. - A user or automation system installs this Skill and processes the unpinned installation declaration.
- The resolver selects the attacker-controlled release because no exact version or cryptographic hash is required.
- Malicious code runs through package build or installation hooks, or later when the installed
nano-pdfcommand is invoked. - The payload operates with the filesystem, process, and network permissions of the account performing installation or execution.
...[truncated 444 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
nano-pdfto a specific version that has been independently reviewed, such as an exactpackage==versiondeclaration supported by the Skill installer. - Require cryptographic hashes through a lock file or equivalent hash-verification mechanism.
- Configure installation to use a trusted package index explicitly and prohibit untrusted fallback indexes.
- Review the pinned distribution, including source distributions, wheels, build configuration, dependencies, and installation hooks.
- Test dependency updates in an isolated environment and update the pin only after review.
- Perform installation and PDF processing under a least-privileged account or sandbox with restricted filesystem and network access.
- Retain dependency provenance and integrity information so deployments can reproduce the reviewed artifact.
- Pin
