T08 · Insecure Dependencies
- Location
README.md:81- Finding
Unpinned Third-Party Executable Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
README.md:81-88; additional dependency declaration atworkflow.json:55-57
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
README.md:81-88:bash # summarize CLI npm install -g @openclaw/summarize-cli # sherpa-onnx TTS pip install sherpa-onnx # Or use a precompiled version brew install sherpa-onnx # macOSworkflow.json:55-57:json "source": "clawhub", "clawhub_id": "steipete/clawdis/sherpa-onnx-tts", "role": "audio-generator",Technical Analysis
The installation instructions do not pin exact package versions, verify integrity hashes, or identify immutable release artifacts. Consequently, package managers resolve mutable registry content at installation time. The ClawHub dependency is similarly identified only by a mutable Skill identifier, without a reviewed version, commit, or artifact digest.
Installing the npm package globally increases the potential effect of a compromised dependency because package installation hooks and executables may run with the invoking user's permissions and become available system-wide for that user. The audit did not establish that any currently referenced package is malicious; the vulnerability is the absence of controls that ensure users execute the same dependency versions that were reviewed.
Attack Path
- An attacker compromises an upstream publisher account, package registry release, transitive dependency, or mutable ClawHub artifact.
- The attacker publishes a malicious release under an existing referenced package or Skill identifier.
- A user follows the documented unversioned installation commands, or the workflow resolves the mutable ClawHub dependency.
- The package manager downloads the attacker-controlled version because no version, integrity hash, or immutable revision is enforced.
- Malicious installation hooks or runtime code ex ...[truncated 937 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every npm, Python, and Homebrew dependency to a specific reviewed version.
- Commit appropriate lockfiles and enable integrity verification for all resolved transitive dependencies.
- Reference the ClawHub Skill through an immutable version, commit, or cryptographic artifact digest rather than only a mutable identifier.
- Verify package signatures, checksums, publisher identity, and artifact provenance before installation.
- Avoid global npm installation. Install dependencies in a project-local, isolated environment with minimal permissions.
- Disable or carefully inspect package lifecycle scripts where operationally possible.
- Use an approved internal mirror or allowlist and continuously scan direct and transitive dependencies for compromise and known vulnerabilities.
- Document trusted download origins and a controlled dependency-update review process.
