T08 · Insecure Dependencies
- Location
SKILL.md:78- Finding
Unpinned Third-Party Dependencies and Unverified External Skill Execution
- Content
View full analysis
/skills/huo15-openclaw-office-doc/scripts/create-word-doc.py ` --output "<下载目录>\ASR_纪要_YYYY-MM-DD_HHmmss.docx" ` --title "会议纪要 - YYYY-MM-DD" ` --content @"<临时 markdown 文件路径>" ` --doc-format 会议纪要 ` --company-name "会议纪要" ` --no-title-block ``` ### Technical Analysis The installation commands do not specify reviewed versions, cryptographic hashes, a lockfile, or an explicitly trusted package index. Consequently, the code installed and imported may change between executions. Package installation can execute package build logic, while later imports and command execution run the installed package with the invoking user's privileges. The Word-generation workflow additionally executes `create-word-doc.py` from another Skill that is not included in the audited project. Its implementation and integrity therefore cannot be verified from this package. This does not establish that the external Skill is malicious, but it creates an unverified supply-chain boundary. ### Attack Path 1. An attacker compromises a referenced package, one of its transitive dependencies, or a package index configured in the local pip environment. 2. Alternatively, an attacker modifies or substitutes the separately installed `huo15-openclaw-office-doc` Skill. 3. A user follows the documented installation or Word-generation instructions. 4. Pip installs attacker-controlled package content, or Python executes the substituted external script. 5. Malicious insta ...[truncated 706 chars]- Remediation
View remediation
