T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Third-Party Packages and Mutable External Installer
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:30-58
Vulnerability Type: Supply-chain exposure through unpinned dependencies and a mutable external installer
Risk Level: MediumVulnerable Code
markdown **Recommended order (TO C):** (1) OpenClaw installed and **default model + provider auth** configured. (2) **Python 3.10+ verified** (`python3 --version`) *before* venv / `pip install`. (3) `pip install powermem` and `pmem` available to the gateway (PATH or `pmemPath`). (4) Install the **memory-powermem** plugin. The curl **`install.sh`** deploys the plugin and OpenClaw entries; with **`-y`** it may still create **`~/.openclaw/powermem/powermem.env`** as an *optional* template—it does **not** run `pip install powermem`. `openclaw --version`. If missing: `npm install -g openclaw`, `openclaw onboard`. - `pip install powermem`. `openclaw plugins install /path/to/memory-powermem`, or **`install.sh`** from [INSTALL.md](https://github.com/ob-labs/memory-powermem/blob/main/INSTALL.md).Equivalent unpinned installation instructions also appear in
config-reference.md:10-10,config-reference.md:34-34, andpowermem-intro.md:33-33.Technical Analysis
The installation procedure does not pin
powermemoropenclawto reviewed versions and does not require package hashes, signed artifacts, or lock files. Consequently, running the documented commands installs whichever package release the registries currently resolve.The plugin installation is also delegated to instructions and an
install.shhosted in an external repository. The URL refers to the mutablemainbranch rather than a reviewed commit. Although the project itself does not contain or directly execute a remote script, following the documented external installation path allows its effective behavior to change after this skill has been audited.This creates a supply-chain trust boundary in which registry maintainers, compromised publishe ...[truncated 1562 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every package to a reviewed version, for example by documenting exact
powermemandopenclawversions. - Use dependency lock files and cryptographic hashes, such as pip hash-checking mode, where supported.
- Reference the plugin repository by an immutable commit hash or signed release rather than the
mainbranch. - Include or vendor the reviewed installer in the audited artifact, or require users to download and inspect it before execution.
- Verify release signatures and published checksums before installation.
- Avoid global npm installation where possible. Install into a constrained user environment without administrator privileges.
- Run installation in a virtual environment or isolated container and apply least-privilege filesystem and network controls.
- Document the exact tested dependency versions and establish a controlled process for reviewing upgrades.
- Pin every package to a reviewed version, for example by documenting exact
