T08 · Insecure Dependencies
- Location
skill.yaml:107- Finding
Unpinned Registry Dependencies Execute Mutable Third-Party Code
- Content
View full analysis
=1.0.0" optional_dependencies: - name: spidershield install: "pip install spidershield" purpose: "Required for scan, audit-config, fix, pin, scan-all" fallback: "check command works without installation (API-only)" ``` `README.md:8-16`: ```bash npx clawhub install spidershield ``` ```bash pip install spidershield ``` `SKILL.md:19-20`: ```bash pip install spidershield ``` ### Technical Analysis The documented installation commands retrieve packages from external registries without pinning an exact version or verifying an integrity hash. The `spidershield` dependency contains the substantive implementation for scanning files, auditing configuration, modifying `~/.openclaw`, and maintaining pin data, but that implementation is not included in the audited project. Consequently, the code executed by these commands may differ from the code reviewed at publication time. A compromised maintainer account, malicious package release, registry compromise, dependency confusion event, or incompatible future update could cause arbitrary package installation or runtime code to execute under the user's account. The privacy claims for local commands cannot be fully verified from this repository because their behavior is delegated to this mutable external package. ### Attack Path 1. An attacker compromises the relevant registry package, publisher account, or distribution channel. 2. The attacker publishes a malicious version under the expected package name. 3. A user follows the documented `pip install spidershield` or unversioned `npx` installation instruction. 4. The package manager retrieves the current attacker-controlled release. 5. Package installation hooks ...[truncated 867 chars]- Remediation
View remediation
