T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party Python Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 4
Vulnerability Type: Unpinned package installation and software supply-chain exposure
Risk Level: MediumVulnerable Code:
yaml metadata: {"openclaw":{"requires":{"bins":["curl","python3"]},"install":[{"id":"python","kind":"pip","package":"requests","bins":[],"label":"Install requests (pip)"}]}}Technical Analysis
The installation metadata declares the third-party Python package
requestswithout specifying an audited version or cryptographic hash. Consequently, the package resolver may install different artifacts over time based on the state of the configured package index and dependency graph.Although
requestsis a legitimate package and there is no evidence that the Skill intentionally selects a malicious dependency, the absence of version and integrity constraints weakens build reproducibility. A compromised upstream release, package index, transitive dependency, or resolver configuration could introduce attacker-controlled code during installation or subsequent execution.Attack Path
- A user or automated Skill installer processes the installation metadata in
SKILL.md. - The installer invokes
pipto resolve and install the unpinnedrequestspackage and its dependencies. - An attacker compromises an eligible upstream artifact, dependency, package index, or package-resolution path.
- The resolver downloads the attacker-controlled artifact because no fixed version and hash are enforced.
- Malicious installation or runtime code executes under the identity and permissions of the account installing or invoking the Skill.
This path requires a compromise or manipulation of the dependency supply chain; the reviewed project itself contains no embedded malicious payload.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the privileges of the user or service performing package installati ...[truncated 305 chars]
- A user or automated Skill installer processes the installation metadata in
- Remediation
View remediation
Remediation Suggestions
- Pin
requeststo a specifically reviewed version rather than allowing unrestricted resolution. - Enforce artifact integrity with cryptographic hashes, such as a hash-locked requirements file installed with
pip --require-hashes. - Lock and audit all transitive dependencies, not only the direct package.
- Configure an explicit trusted package index or an internally controlled dependency mirror.
- Integrate dependency vulnerability and provenance checks into release maintenance.
- Consider replacing
requestswith Python's standard-library HTTP client if eliminating the external dependency is practical.
- Pin
