T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned Third-Party Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 6
Vulnerability Type: Unpinned dependency installation from a package registry
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: {"openclaw":{"emoji":"🔐","os":["linux","darwin"],"requires":{"bins":["agentpass"],"env":["AGENTPASS_URL","AGENT_TOKEN"]},"install":[{"id":"pip-agentpass","kind":"uv","package":"agentpass","bins":["agentpass"],"label":"Install agentpass CLI"}]}}Technical Analysis
The installation metadata requests the
agentpasspackage by name without specifying an exact version or verifying a package hash. Consequently, the installed artifact depends on whichever release the configured package registry resolves at installation time.This creates a supply-chain risk because the installed code can change independently of the reviewed skill. A compromised maintainer account, compromised package registry, malicious future release, or dependency-resolution manipulation could cause users to install code that was not covered by this audit.
This finding does not establish that the current
agentpasspackage is malicious. The weakness is the absence of deterministic version and integrity controls when obtaining executable third-party code.Attack Path
- An attacker compromises the package publisher, distribution account, registry, or another relevant dependency-distribution component.
- The attacker publishes a malicious release under the expected
agentpasspackage name. - A user or skill manager processes the installation declaration and resolves
package: "agentpass"to the attacker-controlled release. - The package is installed and its
agentpassexecutable is subsequently invoked according to the instructions inSKILL.md. - The malicious executable runs with the privileges of the process invoking the skill and can access resources available to that process.
Impact Assessment
Successful exploitat ...[truncated 690 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
agentpassto a specific, reviewed version rather than resolving the latest available release. - Require cryptographic hash verification for the exact package artifact where the installation framework supports it.
- Use a lockfile or equivalent reproducible dependency manifest that records resolved versions and integrity hashes, including transitive dependencies.
- Retrieve packages only from an explicitly configured, trusted registry or an internally controlled package mirror.
- Review package provenance and signatures before updating the pinned version.
- Run the installed CLI under a dedicated, least-privileged account or sandbox with minimal filesystem and network access.
- Provide
AGENT_TOKENonly to the command that requires it, use a narrowly scoped token, and avoid exposing the token to unrelated installation hooks or processes. - Add automated dependency monitoring, but require security review before accepting package updates.
- Pin
