T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Go Dependency Allows Unreviewed Executable Changes
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8-12
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Mediumyaml install: - kind: go module: github.com/openclaw/gitcrawl/cmd/gitcrawl@latest bins: - gitcrawlTechnical Analysis
The installation configuration uses the mutable Go version selector
@latest. Consequently, installations performed at different times can resolve to different source revisions without any corresponding change to the reviewed Skill package.The dependency source is consistent with the declared Gitcrawl project and there is no evidence that its current contents are malicious. However, the lack of an immutable version pin creates a supply-chain risk: an upstream compromise, malicious release, or inadvertently vulnerable future release could cause the installer to build and install code that was not covered by this audit.
Attack Path
- An attacker compromises the upstream repository, maintainer account, or release process for
github.com/openclaw/gitcrawl. - The attacker publishes a new version containing malicious behavior.
- A user installs the Skill after that release.
- The Go installer resolves
@latestto the attacker-controlled version and builds thegitcrawlexecutable. - The Agent subsequently invokes the installed executable during GitHub issue or pull-request triage.
- The compromised executable operates with the privileges and environment available to the Agent process.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user or Agent performing the installation and invocation. Depending on the runtime environment, this could expose local repository data, cached GitHub archives, environment variables, or available GitHub credentials. It could also perform unauthorized filesystem, network, or GitHub operations within the permissions granted to ...[truncated 208 chars]
- An attacker compromises the upstream repository, maintainer account, or release process for
- Remediation
View remediation
Remediation Suggestions
Replace
@latestwith a specific, audited semantic version or immutable commit reference. Review that exact revision before distribution and update it only through an explicit dependency-review process.Where supported, verify downloaded module and release integrity using trusted checksums or signatures. Automated dependency updates should produce reviewable changes, run security checks, and require approval before the pinned revision is advanced. Installation documentation should also identify the expected version so operators can verify the resulting binary.
