T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Executable Dependency Installed from a Mutable Upstream Revision
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–12
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
yaml install: - kind: go module: github.com/openclaw/slacrawl/cmd/slacrawl@latest bins: - slacrawlTechnical Analysis
The installation configuration retrieves and builds the
slacrawlexecutable using the mutable Go version selector@latest. The installed source revision can therefore change after this skill has been reviewed, without any corresponding modification to the audited project.This creates a supply-chain risk because installation implicitly trusts whichever upstream release is considered latest at installation time. No immutable version, commit hash, checksum, or provenance verification is specified. If the upstream repository, maintainer account, release process, or dependency chain is compromised, an attacker could publish altered code that is subsequently installed under the expected
slacrawlname.This finding concerns dependency immutability and does not establish that the current upstream package is malicious.
Attack Path
- An attacker compromises the upstream repository, a maintainer account, its release process, or a relevant dependency.
- The attacker publishes a malicious revision or release that resolves as
github.com/openclaw/slacrawl/cmd/slacrawl@latest. - A user or automated environment installs the skill dependency.
- The installer resolves
@latest, downloads the changed source, builds it, and installs the resultingslacrawlexecutable. - The skill later invokes commands such as
slacrawl doctor,slacrawl status,slacrawl sync, orslacrawl search, causing the compromised executable to run with the invoking process's privileges.
Impact Assessment
Successful exploitation could allow arbitrary behavior within the privileges of the account that installs or exe ...[truncated 516 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a reviewed, explicit semantic version or immutable commit identifier, for example:yaml module: github.com/openclaw/slacrawl/cmd/slacrawl@vX.Y.Z - Establish a controlled update process that reviews upstream changes before advancing the pinned version.
- Verify release provenance, signatures, or checksums where supported by the installation framework.
- Generate and retain dependency metadata or a software bill of materials for the reviewed release.
- Install and execute the binary with least privilege, restricting filesystem, credential, and network access to what archive operations require.
- Avoid exposing Slack API tokens to the process unless API synchronization or protected thread/DM hydration is explicitly requested.
- Replace
