T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Third-Party Python Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:10-13,SKILL.md:25-27, andmetadata.json:20-22
Vulnerability Type: Unpinned external dependency
Risk Level: MediumVulnerable Code
SKILL.md:10-13:yaml install: - kind: uv package: sense-wonder bins: []SKILL.md:25-27:bash pip install sense-wondermetadata.json:20-22:json "install": { "pip": "sense-wonder" },Technical Analysis
The project directs users and agents to install the externally hosted
sense-wonderPython package without an exact version constraint or cryptographic artifact hash. Although the project metadata declares version0.1.2, none of the installation specifications enforce that version.Consequently, package resolution depends on the registry contents at installation time. The downloaded artifact can differ from the package that existed when this skill was reviewed. The repository contains no local implementation of the package, so statements such as “Zero dependencies” and “Just data and access functions” cannot be verified from the audited files.
This creates a Python supply-chain risk. If the registry account, package release process, package name, or an indirectly selected build artifact is compromised, package installation may process an attacker-controlled source distribution and its build backend. Subsequent imports may also execute attacker-controlled module initialization code.
No evidence establishes that the current external package is malicious. The finding concerns the unsafe, mutable dependency resolution process.
Attack Path
- An attacker compromises the package publisher, release pipeline, or registry-hosted package, or otherwise causes a malicious version to be published under the expected package name.
- A user or agent follows the documented
pip install sense-wonderinstruction, or the OpenClaw installer processes the equivalent ...[truncated 1152 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to the reviewed version in every installation declaration:
bash pip install sense-wonder==0.1.2yaml install: - kind: uv package: sense-wonder==0.1.2 bins: [] -
Require cryptographic hashes for approved distribution artifacts, for example through a generated requirements file used with
pip install --require-hashes. -
Commit a reproducible lock file that records the precise package version, artifact, index source, and any transitive dependencies.
-
Configure installation to use an explicitly trusted package index rather than permitting unreviewed alternative indexes or dependency sources.
-
Verify the published wheel and source distribution against the corresponding repository source in CI. Review build-system configuration and import-time behavior before approving each release.
-
Prefer audited wheels over source distributions where feasible, and disable unnecessary source builds in deployment environments.
-
Perform installation and execution in a least-privilege sandbox without sensitive credentials, unrestricted filesystem access, or unnecessary network access.
-
