T08 · Insecure Dependencies
- Location
SKILL.md:44- Finding
Execution of Unreviewed Remote Code and Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 44-47
Vulnerability Type:T08: Insecure Dependencies
Risk Level: SuspiciousVulnerable Code:
bash git clone https://github.com/openclaw-skills/ai-intelligent-asset-management cd ai-intelligent-asset-management pip install -r requirements.txt python app.pyTechnical Analysis
The supplied skill artifact contains no application implementation or dependency manifest. Instead, its installation instructions direct users to clone a remote repository, install packages from an unreviewed
requirements.txt, and execute an unreviewedapp.py.Because neither the remote source revision nor the dependencies are pinned and included in the audited artifact, the effective code executed by users can differ from the content reviewed here. The remote repository could change after publication, and dependency installation may execute package build or installation hooks. A compromise of the repository, its owner account, or one of its dependencies could therefore introduce arbitrary code into this workflow.
Attack Path
- An attacker compromises the referenced repository, its maintainer account, or a dependency resolved by its
requirements.txt. - The attacker inserts malicious application code, dependency declarations, or package installation hooks.
- A user follows the documented installation procedure and clones the mutable remote repository.
pip install -r requirements.txtinstalls the attacker-controlled dependency content and may execute malicious installation hooks.- The user runs
python app.py, directly executing the unreviewed remote application. - The payload operates with the privileges and environmental access of the user who ran the commands.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the invoking user's privileges. Depending on that user's permissions and environment, th ...[truncated 350 chars]
- An attacker compromises the referenced repository, its maintainer account, or a dependency resolved by its
- Remediation
View remediation
Remediation Suggestions
- Include the complete application source and dependency manifests in the skill package so they can be audited together.
- Pin the remote repository to a reviewed, immutable commit rather than cloning the default branch.
- Pin every Python dependency to an exact version and use a lockfile.
- Require package hashes, such as through
pip install --require-hashes, to detect substituted artifacts. - Verify repository commits and release artifacts using trusted signatures or documented checksums.
- Review all direct and transitive dependencies for provenance, known vulnerabilities, and unexpected installation hooks.
- Run installation and application startup in an isolated, least-privileged environment without unnecessary credentials or host access.
- Ensure the audited commit, dependency lockfile, and integrity metadata are updated and reviewed together for every release.
