T08 · Insecure Dependencies
- Location
scripts/revit_call.py:30- Finding
Unpinned Third-Party Dependencies and Mutable Bridge Code Are Executed
- Content
View full analysis
Vulnerability Details
File Location:
scripts/revit_call.py:30-49; related installation guidance atSKILL.md:51,78
Vulnerability Type: Supply-chain exposure through unpinned dependencies and externally maintained executable code
Risk Level: HighVulnerable Code
python # Build the uv command cmd_parts = [ "uv", "run", "--with", "httpx", "--with", "click", "python", "-m", "openclaw_bridge.cli" ] # Add the subcommand cmd_parts.extend(command.split()) # Add arguments for a tools call if "tools call" in command and args: cmd_parts.extend(["--args", json.dumps(args)]) try: result = subprocess.run( cmd_parts, cwd=BRIDGE_DIR, capture_output=True, text=True, timeout=60, env={**subprocess.os.environ, "REVIT_MCP_URL": REVIT_MCP_URL} )The associated setup instructions execute an externally cloned repository without identifying a reviewed commit:
markdown 2. **Linux side** has installed openclaw-bridge (`git clone https://github.com/ryanchan720/openclaw-bridge`)bash uv run python -m openclaw_bridge.cli healthTechnical Analysis
The wrapper executes the
openclaw_bridge.climodule from the directory selected byOPENCLAW_BRIDGE_DIR. The documented installation process obtains that code from a mutable Git repository without pinning a commit, tag digest, or signed release.The invocation also asks
uvto providehttpxandclickwithout version constraints or integrity hashes. Dependency resolution can therefore change after the Skill has been reviewed. A malicious or compromised upstream package release, package index, bridge repository, or update could introduce code that is executed automatically when the wrapper runs.This is a supply-chain trust-boundary issue rather than evidence that the currently reviewed source is malicious. The reviewed project contains ...[truncated 1350 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
openclaw-bridgeto a reviewed commit hash or a cryptographically signed, immutable release. - Pin exact versions of
httpx,click, and all transitive dependencies in a committed lockfile. - Require package hashes and use a trusted, controlled package index where possible.
- Install dependencies into a dedicated virtual environment during a controlled installation phase instead of resolving them during each command invocation.
- Verify the bridge directory against an expected commit or artifact digest before execution.
- Run the bridge under a dedicated low-privilege account or sandbox with only the filesystem and network access required for Revit operations.
- Avoid forwarding the entire parent environment. Construct a minimal environment containing only required variables.
- Add dependency vulnerability scanning and reproducible-build checks to release validation.
- Pin
