T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Unpinned Remote Repository and Dependencies Are Installed and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38-41
Vulnerability Type: Unreviewed remote code and insecure dependency installation
Risk Level: HighComplete Code Snippet:
bash git clone https://github.com/openclaw-skills/ai-intelligent-demand-forecasting cd ai-intelligent-demand-forecasting pip install -r requirements.txt python app.pyTechnical Analysis
The installation instructions clone a mutable external Git repository without selecting a reviewed commit or validating its contents. They then install dependencies from a remotely obtained
requirements.txtand execute the remotely obtainedapp.py.The audited package does not contain
requirements.txt,app.py, a dependency lock file, package hashes, or a pinned repository revision. The effective application and dependency set therefore cannot be verified from the supplied artifact and may change after this skill has been reviewed. Python packages can execute code during installation through build backends or setup logic, whilepython app.pydirectly executes the downloaded application.The repository organization in the clone URL also differs from the author declared in
skill.json, which weakens provenance clarity but does not independently prove malicious behavior.Attack Path
- An attacker compromises the referenced repository, gains control of a dependency, or causes unsafe dependency resolution.
- The attacker adds malicious behavior to
app.py, package installation logic, or a dependency selected byrequirements.txt. - A user follows the documented commands and clones the current, mutable repository state.
pip install -r requirements.txtexecutes malicious package build or installation behavior, orpython app.pyruns the altered application.- The payload performs actions with the privileges and environmental access of the invoking user.
Impact Assessment
Successful exploitation co ...[truncated 640 chars]
- Remediation
View remediation
Remediation Suggestions
- Include the implementation and dependency manifests in the audited skill package so the executed code can be reviewed with the documentation.
- Pin the external repository to a specific, reviewed commit hash rather than cloning and executing its default branch.
- Use an exact dependency lock file and require cryptographic hashes for all packages, such as with
pip install --require-hashes. - Verify repository provenance and align the documented publisher, repository owner, and author metadata.
- Validate downloaded artifacts using trusted signatures or checksums before installation or execution.
- Install dependencies inside an isolated virtual environment or container using a non-privileged account.
- Restrict filesystem, credential, and network access to the minimum required for forecasting operations.
- Review
app.py, all transitive dependencies, and package build scripts before permitting execution.
