T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned External Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:28-52; mirrored inSKILL-EN.md:28-52andSKILL-ZH.md:28-52
Vulnerability Type: Unpinned third-party package and source installation
Risk Level: MediumVulnerable Code
bash # Install globally for CLI access npm install -g openclaw-identity-trust # Verify installation identity-trust --versionbash # Clone repository git clone https://github.com/ZhenRobotics/openclaw-identity-trust.git cd openclaw-identity-trust # Install dependencies npm install # Build npm run buildbash # Check CLI is working identity-trust info # Create your first DID identity-trust did createTechnical Analysis
The Skill directs users or agents to retrieve and execute mutable third-party code without pinning an exact npm package version, repository commit, dependency lock state, or integrity digest.
npm install -g openclaw-identity-trustresolves the package version at installation time and may execute npm lifecycle scripts. The global installation also exposes package-provided command aliases across the user's environment. The alternative GitHub procedure clones the current default branch and subsequently runsnpm installandnpm run build, allowing both repository content and transitive dependencies to differ from what was reviewed.The audited artifact contains documentation only. It does not include the referenced implementation, package manifest, lockfile, installation scripts, or cryptographic integrity metadata. Consequently, the external package's implementation and security claims cannot be verified from this project.
This finding does not establish that the current external package is malicious. It establishes an unsafe supply-chain boundary in which code executed later is not cryptographically or immutably tied to the reviewed Skill.
Attack Path
- A user or AI agent loads the Skill and follows its re ...[truncated 1505 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the npm dependency to a reviewed, exact version rather than relying on the latest matching release:
bash npm install --global openclaw-identity-trust@1.0.0 -
Pin source installations to a reviewed commit hash and verify the checked-out revision before installation:
bash git clone https://github.com/ZhenRobotics/openclaw-identity-trust.git cd openclaw-identity-trust git checkout --detach <reviewed-commit-hash> test "$(git rev-parse HEAD)" = "<reviewed-commit-hash>" -
Publish and verify signed release artifacts or cryptographic checksums. Document the expected digest in the Skill so the retrieved artifact can be tied to the audited version.
-
Include the implementation,
package.json, and a committed lockfile in the audit scope. Use deterministic installation such asnpm cirather than unconstrainednpm install. -
Review all lifecycle and build scripts before execution. Where compatible with the package, initially install dependencies with lifecycle scripts disabled:
bash npm ci --ignore-scripts -
Avoid global installation where possible. Use a dedicated project environment, container, or otherwise sandboxed unprivileged account with restricted filesystem and network access.
-
Require explicit user confirmation before installing external code, generating DIDs, or creating persistent key material.
-
Protect the identity storage directory with restrictive filesystem permissions, and use a dedicated keystore or operating-system-backed secret store rather than relying solely on a general JSON file.
-
Apply the same corrected installation instructions consistently to
SKILL.md,SKILL-EN.md, andSKILL-ZH.md.
-
