T08 · Insecure Dependencies
- Location
README.md:17- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 17-20
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumbash ## Install ```bash npx clawhub install admapixtext ### Technical Analysis The installation instructions invoke `clawhub` through `npx` without specifying a reviewed package version or integrity constraint. If the package is not already available locally, `npx` can retrieve and execute the version currently resolved by the npm registry. Because the repository does not include a lockfile, package integrity hash, vendored installer, or other mechanism that binds this command to an audited release, the code executed at installation time can differ from the code originally reviewed. This creates a supply-chain trust dependency on the package registry, package publisher account, DNS/TLS infrastructure, and the latest resolved package release. The command is documented rather than automatically executed by the Skill. Exploitation therefore requires a user or deployment process to follow the installation instructions. ### Attack Path 1. An attacker compromises the `clawhub` package, its publisher account, or an associated package-distribution channel. 2. The attacker publishes a malicious version that is selected by the unpinned `npx clawhub` invocation. 3. A user or automated deployment follows the documented installation command. 4. `npx` downloads and executes the attacker-controlled package. 5. The malicious package runs with the privileges and environment access of the installing user. ### Impact Assessment Successful exploitation could permit arbitrary local code execution under the installing user's account. Depending on that account's privileges and environment, the malicious installer could read accessible files and environment variables, steal API credentials, modify user configuration, install additional components, or tamper with other project ...[truncated 269 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the installer to a specifically reviewed release:
bash npx --yes clawhub@<reviewed-version> install admapix - Document the expected npm publisher, package registry, and release provenance so users can verify that they are retrieving the intended package.
- Publish and verify package integrity or signed provenance where supported.
- Prefer a locked installation workflow for automated deployments rather than resolving the latest release at execution time.
- Run the installation using a minimally privileged account and avoid exposing unrelated secrets in its environment.
- Apply the same correction to the equivalent command in
README_CN.md, lines 17-20.
- Pin the installer to a specifically reviewed release:
