T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Unpinned External Package and Source Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 22–33
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
markdown **Via npm (Recommended)** ```bash npm install -g openclaw-personal-cfoVia GitHub
bash git clone https://github.com/ZhenRobotics/openclaw-personal-cfo.git cd openclaw-personal-cfo npm install npm run buildtext ### Technical Analysis The documented installation procedures retrieve and execute mutable third-party content without pinning a reviewed npm package version, Git commit, dependency lockfile, or integrity digest. The recommended global npm installation can run package lifecycle scripts and place executable aliases on the user's `PATH`. The alternative procedure clones the repository's mutable default branch, installs its dependency graph, and runs its build scripts. Consequently, the code executed by these commands can change after this Skill artifact has been reviewed. The external package implementation and dependency manifests are not included in the audited project. Therefore, the claims in `SKILL.md` that the tool stores all data locally and makes no external API or analytics calls cannot be verified from the available artifact. This finding identifies supply-chain exposure rather than establishing that the current external package is malicious. ### Attack Path 1. An attacker compromises the npm package, upstream repository, maintainer account, release process, or a transitive dependency. 2. The attacker publishes a modified release or changes content on the repository's default branch. 3. A user or agent follows the installation instructions in `SKILL.md`. 4. `npm install`, an npm lifecycle script, or `npm run build` executes the attacker-controlled code with the privileges of the installing user. 5. The malicious code can access resources available to that user, including the advertised local financial data, and may alter installed exec ...[truncated 713 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm package to a specific reviewed version rather than installing the latest mutable release.
- Pin source installations to a reviewed Git commit hash or signed release tag instead of cloning and building the default branch.
- Include a committed lockfile and use reproducible installation commands such as
npm ci. - Publish and verify package integrity hashes, signed release artifacts, and npm provenance attestations.
- Audit all npm lifecycle and build scripts before execution; use
--ignore-scriptswhen lifecycle scripts are unnecessary. - Prefer a project-local installation over a global installation to reduce
PATHexposure and limit unintended system-wide effects. - Bundle the reviewed implementation and dependency metadata with the Skill, or otherwise make them available for the same audit.
- Document the exact network behavior and data handling of the CLI, and verify the local-only privacy claims against the pinned source version.
