T08 · Insecure Dependencies
- Location
index.ts:52- Finding
Unpinned Runtime Package Retrieval and Execution via npx
- Content
View full analysis
Vulnerability Details
File Location:
index.ts, lines 52–54
Vulnerability Type: Runtime supply-chain exposure through implicit package retrieval
Risk Level: MediumVulnerable Code
ts if (existsSync(srcCli)) { return { file: "npx", baseArgs: ["tsx", srcCli] }; }The returned command is subsequently executed here:
ts const result = spawnSync(bin.file, [...bin.baseArgs, ...args], { cwd: workdir, encoding: "utf-8", timeout, env: { ...process.env }, });Technical Analysis
When the globally installed
opentanglcommand is unavailable andsrc/cli.tsexists in the configured workspace, the plugin falls back tonpx tsx src/cli.ts.The
tsxpackage is neither pinned as an exact runtime dependency nor invoked withnpx --no-install. If it is unavailable locally,npxmay resolve, download, and execute package code from the configured npm registry at runtime. Consequently, the code that executes can differ from the code reviewed with this plugin.This behavior is not required by the plugin's minimum declared functionality because its documentation already identifies an installed and configured OpenTangl environment as a prerequisite. It also broadens the trust boundary from the installed plugin and OpenTangl executable to the current registry configuration and whichever
tsxversion is selected at invocation time.Although command arguments are safely passed without a shell, preventing ordinary shell-metacharacter injection, that protection does not mitigate package-resolution attacks. The spawned process also inherits the complete OpenClaw environment, including documented AI-provider API keys and potentially unrelated secrets.
Attack Path
- The configured
opentanglexecutable is absent or fails the startup--versionprobe. - The configured workspace contains
src/cli.ts, selecting thenpx tsxfallback. - No trusted local
tsxexecutable ...[truncated 1096 chars]
- The configured
- Remediation
View remediation
Remediation Suggestions
- Remove the automatic
npxfallback and require a preinstalled, administrator-configured OpenTangl executable. - If TypeScript-source execution must remain supported, add
tsxas an exact, integrity-locked dependency and invoke its local binary directly. - If retaining
npx, usenpx --no-install tsx ...so a missing local dependency causes a safe failure rather than a network installation. - Avoid floating version selection. Pin and review the exact
tsxversion and regenerate the lockfile from the minimal required dependency set. - Validate that the selected executable resolves to an expected trusted path before launching it.
- Replace
{ ...process.env }with an explicit environment allowlist containing only variables required by OpenTangl. Pass provider credentials only to commands that need them. - Run the plugin and OpenTangl CLI under a restricted service account with narrowly scoped repository and GitHub permissions.
- Remove the automatic
