T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party Executable npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:5
Vulnerability Type: Unpinned executable dependency
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: { "openclaw": { "emoji": "📖", "requires": { "bins": ["inkos", "node"], "env": ["OPENAI_API_KEY"] }, "primaryEnv": "OPENAI_API_KEY", "homepage": "https://github.com/Narcooo/inkos", "install": [{ "id": "npm", "kind": "node", "package": "@actalk/inkos", "label": "Install InkOS (npm)" }] } }Technical Analysis
The Skill descriptor directs the platform to install the executable
@actalk/inkospackage from npm without specifying an exact version or package integrity hash. Consequently, installation may resolve to a package release published after this Skill was reviewed.The audited project contains only
SKILL.md; it does not include the dependency's executable source code. Claims elsewhere in the document—such as the absence of installation hooks, telemetry, or writes outside the project directory—therefore cannot be independently verified from the supplied artifact. Even if those claims accurately describe the current package, an unpinned future release could behave differently.This constitutes a supply-chain trust weakness rather than evidence that the current npm package is malicious.
Attack Path
- An attacker compromises the npm publisher account, package publication pipeline, or another component of the package's release process.
- The attacker publishes a malicious release under the legitimate
@actalk/inkospackage name. - A user or automation system installs the Skill after that release is published.
- Because no exact version or integrity value is specified, npm resolves the dependency to the attacker-controlled release.
- The package's code executes when the user invokes
inkos, potentially inheriting the user's local permissions, working-directory access, and environment. - The malicious release can access or ...[truncated 612 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@actalk/inkosto a specific, reviewed version rather than allowing unconstrained resolution. - Record and verify the expected npm package integrity hash or lockfile integrity metadata.
- Review the package contents and transitive dependency tree before approving each upgrade.
- Treat version updates as security-sensitive changes requiring a new audit.
- Where practical, vendor or otherwise retain the reviewed source artifact so the executed implementation corresponds to the audited version.
- Run the CLI with least privilege and expose only the environment variables and project directories required for the current operation.
- Continue using environment-variable-based credential configuration, but ensure secrets are scoped to the process and are not committed to source control.
- Pin
