T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code
json metadata: {"clawdbot":{"emoji":"📄","requires":{"bins":["nano-pdf"]},"install":[{"id":"uv","kind":"uv","package":"nano-pdf","bins":["nano-pdf"],"label":"Install nano-pdf (uv)"}]}}Technical Analysis
The installation metadata directs
uvto install thenano-pdfpackage without specifying an exact version, integrity hash, or verified artifact source. Dependency resolution can therefore select a package release that was published or modified after this skill was audited.The dependency's implementation is not included in the project, so its installation behavior, transitive dependencies, and runtime behavior cannot be verified from the audited artifact. Python packages may execute package-controlled code during installation or when their command-line entry points are invoked. This creates a supply-chain trust boundary in which a compromised maintainer account, malicious future release, or compromised transitive dependency could introduce arbitrary behavior.
The audit found no evidence that the skill itself intentionally retrieves a malicious package, and no embedded malicious code, persistence mechanism, privilege escalation, data-exfiltration instruction, or instruction hijacking was present. The risk arises specifically from the unpinned external dependency.
Attack Path
- An attacker compromises the upstream
nano-pdfdistribution channel, maintainer account, or one of its unresolved dependencies. - The attacker publishes a malicious release that remains compatible with the unconstrained package name.
- A user or agent installs the skill dependency through the declared
uvinstallation method. uvresolves and installs the attacker-controlled release because no audited version or artifact hash is enforced.- Malicious code execute ...[truncated 747 chars]
- An attacker compromises the upstream
- Remediation
View remediation
Remediation Suggestions
- Pin
nano-pdfto a specifically reviewed version rather than resolving the latest available release. - Use a lock file and require cryptographic hashes for the package and all transitive dependencies.
- Retrieve artifacts only from a trusted package index or an internally controlled mirror.
- Verify package provenance, publisher identity, signatures, and release integrity where supported.
- Review the pinned package's source code, build configuration, command entry point, and dependency graph before approval.
- Install and execute the utility in a sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and non-administrative privileges.
- Establish an explicit dependency-update process in which new versions are reviewed and tested before the pin and hashes are changed.
- Pin
