T08 · Insecure Dependencies
- Location
SKILL.md:81- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 81–83
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: MediumComplete Code Snippet:
bash npx clawhub@latest install binance-event-contract-ict-recognizer --dir /workspace/skillsTechnical Analysis
The documented installation command invokes
npxwith the mutablelatesttag. If the requested package is not already available in a trusted local cache,npxcan retrieve it from the configured npm registry and execute its package entry point or installation logic immediately.Because
latestdoes not identify an immutable, previously audited version, the code executed by this command can change after the Skill documentation has been reviewed. Theclawhubpackage and its transitive dependencies are not included in this project, so their behavior, provenance, and integrity cannot be verified from the audited artifact.This creates a supply-chain trust boundary in which compromise of the package publisher, registry account, release process, package contents, or transitive dependencies could convert the documented installation procedure into arbitrary code execution.
Attack Path
- An attacker compromises the
clawhubpackage publisher, its release pipeline, or a relevant dependency. - The attacker publishes a malicious release and assigns or causes it to receive the
latestdistribution tag. - A user follows the installation command in
SKILL.md. npxretrieves the mutable package release and executes its installation logic with the invoking user's permissions.- The malicious installer can alter
/workspace/skillsand perform any other operation permitted to that user.
Impact Assessment
Successful exploitation would provide code execution with the privileges of the user running the installation command. Depending on that user's permissions and environment, the malicious packa ...[truncated 480 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version; do not use a mutable version range or distribution tag. - Verify the downloaded artifact using an approved cryptographic integrity digest or signed provenance before execution.
- Review the selected package version and its transitive dependency tree before publishing the installation instructions.
- Use a lockfile or equivalent immutable dependency manifest where supported.
- Prefer a trusted internal registry or a vetted distribution channel with access controls, package signing, and release auditing.
- Run installation in a sandbox or least-privileged environment without production credentials or unnecessary filesystem access.
- Disable or carefully review dependency lifecycle scripts where the installation workflow permits it.
- Document the expected package publisher, version, digest, and verification procedure so users can detect substituted artifacts.
- Replace
