T08 · Insecure Dependencies
- Location
scripts/extract.py:25- Finding
Automatic Installation of Unpinned Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a real MP4-to-MP3 skill, but it automatically changes Python environments and downloads executable dependencies in ways users should review before installing.
Review this skill before installing. It can read a chosen video folder and write MP3 outputs, which matches its purpose, but it also changes Python package state, uses a shared virtual environment, and may download and run FFmpeg automatically. Prefer a version that requires preinstalled, trusted FFmpeg and pinned dependencies in a private venv, and avoid running the documented sudo symlink workaround unless you fully understand the system-wide effect.
scripts/extract.py:25Automatic Installation of Unpinned Third-Party Dependencies
scripts/ensure_package.py:27Import-Time Forced Replacement of Foundational Host Python Packages
scripts/extract.py:38Unverified Remote FFmpeg Binary Download and Execution
scripts/config.py:27Virtual Environment Shared Outside the Skill Security Boundary
The chained command sudo apt update && sudo apt install python3-venv combines multiple privileged operations into a single copy-paste step. In agent-oriented environments, chained privileged commands reduce review opportunities and make it easier for unsafe or unintended actions to be executed wholesale.
**修复步骤 (Linux示例):**
\# 1\. 安装 venv 支持
sudo apt update && sudo apt install python3-venv
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)
sudo ln \-s /usr/bin/python3 /usr/bin/python
\# 3\. 重启服务
If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.
If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.
If the actual implementation does not perform media extraction at all and instead focuses on unrelated logging or path management, the skill is materially deceptive about what it does. Even if not overtly malicious, such mismatch undermines trust and can conceal unwanted file operations or create a pathway for future abuse under an innocuous label.
This file implements a broad package-installation utility that can manage arbitrary dependencies and sources, which materially exceeds the needs of batch MP4-to-MP3 conversion. Scope expansion is dangerous because it introduces code-fetching and environment-modifying capabilities unrelated to the advertised function, a common sign of unnecessary attack surface or covert functionality.
The module mutates the Python packaging environment immediately on import by reinstalling packaging, setuptools, and wheel. Import-time side effects are dangerous because simply loading the module triggers system modifications without informed action from the user, and they affect all consumers of the module, not just an explicit setup flow.
The code explicitly supports installation from remote git/HTTP sources and local archives, which can fetch and execute untrusted third-party code. This is a severe supply-chain risk and effectively gives the skill a code-download-and-run capability unrelated to MP4-to-MP3 extraction, making the context substantially more dangerous.
Code enumerates, copies, or searches environment variables for secrets. Bulk environment access can collect credentials unrelated to the skill's stated purpose.
sys.exit(1)
# 传递环境变量防止递归
env = os.environ.copy()
env["RUNNING_IN_VENV"] = "true"
logger.info(f" 当前Python: {sys.executable}")
The subprocess-driven FFmpeg installation acquires and executes external code beyond the core purpose of converting files. Because it is automatic and non-interactive, a user invoking a media tool may unknowingly trigger binary download and install behavior that could be abused through supply-chain compromise or unexpected environment modification.
This markdown file describes behavior that recursively scans directories, preserves folder structure, writes extracted MP3 files, and stores logs, but it does not include a clear user-facing warning that the skill will create output files and retain execution logs. For markdown files, missing disclosures about actions affecting user data or system state should be flagged when warnings are omitted.
The README instructs users to run sudo apt update && sudo apt install python3-venv, which normalizes elevated execution for setup. While common for package installation, encouraging root-level commands in skill docs increases risk because users may execute them without understanding system-wide effects, especially in an agent-tooling context.
**修复步骤 (Linux示例):**
\# 1\. 安装 venv 支持
sudo apt update && sudo apt install python3-venv
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)
sudo ln \-s /usr/bin/python3 /usr/bin/python
\# 3\. 重启服务
The README instructs users to create a system-wide symlink with sudo ln -s /usr/bin/python3 /usr/bin/python. Modifying /usr/bin as root can interfere with system tooling, break distributions that intentionally omit python, and conditions users to make privileged persistent changes for a single skill.
\# 1\. 安装 venv 支持
sudo apt update && sudo apt install python3-venv
\# 2\. 建立软链接 (路径请根据实际 Python 安装位置修改)
sudo ln \-s /usr/bin/python3 /usr/bin/python
\# 3\. 重启服务
systemctl \--user restart openclaw-gateway
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The README says users can directly tell the agent phrases like '帮我把…都转成mp3' and '批量把…这些视频转音频…' without defining explicit trigger boundaries, exclusions, or a constrained command format. In a markdown skill description, such broad natural-language activation examples can overlap with ordinary conversation and make invocation scope unclear.
The README suggests a workflow that includes downloading a remote Douyin video even though the skill is presented as a local MP4-to-MP3 extractor and no documented capability here supports safe downloading. This can mislead an agent or user into chaining unrelated tools or unsafe actions against remote content beyond the skill's stated scope.
The skill declares executable behavior that invokes Python via shell but does not define any explicit tool scope or permission boundary. This is dangerous because an agent may execute shell-capable actions without clear least-privilege constraints, increasing the chance of unintended command execution or broader filesystem/process access than users expect.
Overly broad trigger phrases can cause the skill to activate on loosely related everyday requests, including cases where the user did not intend file conversion or shell execution. In a skill that can write files and invoke Python, over-triggering increases the risk of unintended actions and user confusion.
The invocation guidance appears broad enough to capture loosely related requests, including workflows like downloading videos before processing. This expands the operational scope beyond straightforward local conversion and can lead to unintended network or filesystem activity if the agent invokes the skill too aggressively.
The mismatch between the file header branding and the actual behavior obscures the true capability of the module. Mislabeling a package installer as part of an MP4-to-MP3 extractor reduces transparency and can prevent reviewers or users from understanding that the code changes the environment and fetches packages.
This subprocess call invokes pip to force-install a package into the current Python environment. Because it runs as part of an import-time repair routine, it performs privileged system mutation without user consent and can unexpectedly alter dependency state for any workflow that imports this module. In the context of an MP4-to-MP3 skill, modifying packaging internals is unjustified and expands the attack surface.
"""专门为老项目(使用 pkg_resources 的 setup.py)修复 setuptools 版本"""
try:
# 先强制修复损坏的 packaging 包(关键!解决无RECORD文件报错)
subprocess.check_call([
sys.executable, "-m", "pip", "install",
"--verbose", "--ignore-installed", "--no-deps", "packaging==26.1"
])
This call force-reinstalls setuptools and wheel, directly mutating core packaging tools in the active environment. Reinstalling foundational build tooling at import time can break unrelated software, downgrade security posture, or facilitate later installation of untrusted packages. For a media conversion skill, this capability is unnecessary and therefore more suspicious and dangerous.
"--verbose", "--ignore-installed", "--no-deps", "packaging==26.1"
])
# 再安装兼容的 setuptools + wheel
subprocess.check_call([
sys.executable, "-m", "pip", "install",
"--verbose", "--force-reinstall", "setuptools<=81.2.0", "wheel"
])
At line 43 the module causes package installation side effects merely by being imported, with no explicit user-facing disclosure or consent flow. Hidden system-modifying behavior increases the risk of unexpected environment compromise and makes auditing and safe use much harder.
Dynamic import() can load arbitrary modules at runtime, bypassing static analysis and potentially importing malicious code.
# 第一步:尝试 import 检查(最快)
try:
parts = import_name.split('.')
mod = __import__(parts[0])
for part in parts[1:]:
mod = getattr(mod, part)
if sub_import:
The automatic pip execution in this range performs system modification and code installation without a clear user disclosure mechanism. Even if intended for convenience, silent dependency changes and remote code retrieval are dangerous in a user-facing skill and inappropriate for a narrow media-conversion task.
No suspicious patterns detected.