T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party Installation Commands Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 13-24
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumThe installation documentation recommends executing package runners using the mutable
latesttag and installing source directly from a Git repository without pinning a reviewed commit:bash # Install all skills from repo npx skills add https://github.com/barneyjm/camino-skills # Or install specific skills npx skills add https://github.com/barneyjm/camino-skills --skill relationshipVia clawhub:
bash npx clawhub@latest install relationship # or: pnpm dlx clawhub@latest install relationship # or: bunx clawhub@latest install relationshipTechnical Analysis
The Git installation commands reference a mutable repository branch rather than an immutable commit hash or signed release. The package-runner commands similarly use
clawhub@latest, which resolves to whichever package version is current at execution time. Consequently, the code installed or executed by these commands can differ from the version reviewed during this audit.Package runners such as
npx,pnpm dlx, andbunxdownload and execute package code. If the relevant registry account, package, repository, maintainer credentials, or release process is compromised, an attacker could substitute malicious installation logic. The recommendation to install all skills also expands the supply-chain attack surface beyond the code needed for the relationship function.No evidence shows that the currently reviewed project contains such a malicious payload. The vulnerability is the absence of dependency pinning and integrity controls in the documented installation process.
Attack Path
- An attacker compromises the upstream package registry account, Git repository, maintainer credentials, or publishing pipeline.
- The attacker publishes a malicious version under the `latest ...[truncated 1008 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an explicitly reviewed package version, for exampleclawhub@x.y.z. - Pin Git-based installation to an immutable commit SHA or a cryptographically signed release rather than the repository's default branch.
- Publish and verify cryptographic checksums or signatures for installation artifacts.
- Commit and enforce an appropriate lockfile where package-manager workflows support it.
- Recommend installing only the required
relationshipskill instead of all repository skills, unless the additional components have been independently reviewed and are necessary. - Run installation with a non-privileged account in an isolated environment, and do not expose unrelated credentials or sensitive environment variables during installation.
- Establish dependency provenance, maintainer account protection, and release review controls, including multi-factor authentication and protected release workflows.
- Replace
