T08 · Insecure Dependencies
- Location
src/shield-client.ts:212- Finding
Unpinned External Scanner Executes with Access to Sensitive Agent Traffic
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:40-44,README.md:31-45,src/preflight.ts:53-56,src/shield-client.ts:212-216
Vulnerability Type: Unpinned third-party runtime dependency and inconsistent package provenance
Risk Level: HighVulnerable Code and Instructions
SKILL.md:40-44:bash pip install "zugashield[mcp]" npm install zugashield-openclaw-plugin openclaw plugins install ./node_modules/zugashield-openclaw-plugin openclaw restartREADME.md:31-45:bash pip install "zugashield[mcp]"bash cd your-openclaw-directory npm install @zugashield/openclaw-pluginbash cd extensions git clone https://github.com/AntonioCiolworking/zugashield-openclaw-plugin zugashieldsrc/preflight.ts:53-56:ts try { await exec(pythonExe, ["-c", "import zugashield_mcp"]); result.zugashieldMcp = true;src/shield-client.ts:212-216:ts this.transport = new StdioClientTransport({ command: this.config.mcp.python_executable, args: ["-m", "zugashield_mcp.server"], env: this._buildChildEnv(),Technical Analysis
The documented installation commands do not pin exact npm or Python package versions or verify artifact hashes or signatures. The plugin subsequently imports and persistently executes the separately distributed
zugashield_mcpPython module.This external component receives request text, tool names and arguments, response content, and recalled memory through MCP scan calls. Consequently, the component occupies a highly trusted position despite its implementation not being present in the audited project.
Package identity and provenance are also inconsistent.
SKILL.mdrefers to the unscopedzugashield-openclaw-pluginpackage and theZuga-lugaproject, whileREADME.mdrefers to@zugashield/openclaw-pluginand anAntonioCiolworkingrepository. These inconsistencies increase the possibility of ...[truncated 2230 chars]- Remediation
View remediation
Remediation Suggestions
- Pin exact npm and Python package versions rather than using unconstrained installation commands.
- Publish and verify cryptographic hashes for Python wheels and npm release artifacts. Use a locked requirements file with hashes for Python dependencies.
- Standardize the package scope, repository owner, homepage, and installation instructions across
SKILL.md,README.md, andpackage.json. - Enable package provenance and signed releases, and document how users can verify publisher identity before installation.
- Vendor or independently audit the Python scanner implementation because it processes security-sensitive agent traffic and determines enforcement verdicts.
- Run the scanner under a dedicated low-privilege account or sandbox with a read-only filesystem, no access to user home directories, resource limits, and a restricted working directory.
- Disable outbound network access by default. If threat-feed access is required, permit only explicitly configured HTTPS destinations and validate their certificates and update signatures.
- Consider requiring an absolute, administrator-approved Python executable path rather than resolving a generic
pythoncommand throughPATH. - Add automated release checks that reject mismatched repository URLs, package names, unpinned installation examples, and unsigned artifacts.
