T08 · Insecure Dependencies
- Location
SKILL.md:96- Finding
Unpinned npm Package Execution in Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 96–99
Vulnerability Type: Supply-chain risk caused by execution of a mutable third-party package version
Risk Level: MediumComplete Code Snippet:
markdown ## Installation ```bash npx clawhub@latest install binance-event-contract-signal-calculator --dir /workspace/skillstext ### Technical Analysis The documented installation procedure invokes `npx` with `clawhub@latest`. When the package is not already available locally, `npx` can download it from the configured npm registry and execute its package entry point. The `latest` distribution tag is mutable and does not identify an immutable, previously audited release. Consequently, the effective code executed by this command can change after this Skill has been reviewed, without any modification to `SKILL.md`. The artifact does not provide an exact package version, lockfile, integrity digest, or other mechanism for verifying the downloaded package. This is a supply-chain weakness; the audit found no evidence that the package is currently malicious. ### Attack Path 1. An attacker compromises the `clawhub` npm publishing account, its release process, or another relevant package-publication component. 2. The attacker publishes a malicious release and assigns it to the mutable `latest` tag. 3. A user follows the installation command in `SKILL.md`. 4. `npx` retrieves the attacker-controlled package from the configured registry. 5. The package executes with the operating-system permissions and environment available to the installing user. 6. Malicious package lifecycle or application code can perform actions within those permissions before or during installation of the requested Skill. ### Impact Assessment Successful exploitation could permit arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the malicious dependency could r ...[truncated 480 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, audited package version, for exampleclawhub@X.Y.Z. - Verify the selected release's provenance and integrity before documenting it.
- Use a lockfile or an equivalent reproducible dependency mechanism where applicable.
- Pin and verify package integrity using a trusted digest or registry-supported integrity metadata.
- Document the expected trusted registry and reject unexpected registry overrides.
- Execute installation in a least-privileged, isolated environment without unnecessary credentials or sensitive environment variables.
- Review package lifecycle scripts and transitive dependencies before approving version upgrades.
- Treat upgrades as security-sensitive changes requiring renewed review rather than automatically following a mutable distribution tag.
- Replace
