T08 · Insecure Dependencies
- Location
README.md:7- Finding
Unpinned Third-Party Installer and Skill Source
- Content
View full analysis
Vulnerability Details
File Location:
README.md:7-15,SKILL.md:31-34
Vulnerability Type: Supply-chain risk caused by mutable, unverified third-party dependencies
Risk Level: MediumVulnerable Code
README.md:7-15:bash ## Install ```bash npx skills add blammectrappora/chinese-ink-painting-generatorOr with ClawHub:
bash clawhub install chinese-ink-painting-generatortext `SKILL.md:31-34`: ```bash ## Install ```bash npx skills add blammectrappora/chinese-ink-painting-generatortext ### Technical Analysis The documented installation command invokes the `skills` package through `npx` without specifying an immutable package version. The skill source is also identified by a mutable repository or registry name rather than a reviewed commit hash or version. When the requested package is not already available locally, `npx` can download and execute the package currently published under that name. The project does not provide a lockfile, integrity hash, cryptographic signature, pinned installer version, or pinned skill revision. Consequently, the code executed by a future installation may differ from the artifact covered by this audit. No malicious dependency is present in the audited artifact. Exploitation depends on compromise, replacement, or malicious modification of an upstream installer, package release, registry entry, or skill source. ### Attack Path 1. An attacker compromises the account, registry package, repository, or distribution infrastructure associated with the unpinned installer or skill. 2. The attacker publishes a modified release containing malicious installation logic or skill content. 3. A user follows the documented `npx skills add blammectrappora/chinese-ink-painting-generator` command. 4. `npx` resolves and runs the mutable package version available at installation time. 5. The malicious code executes with the permissions of the us ...[truncated 489 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsinstaller to a reviewed, explicit version instead of allowingnpxto resolve the latest release. - Pin the installed skill to an immutable version or commit hash.
- Publish and verify cryptographic integrity hashes or signatures for released artifacts.
- Use a lockfile or equivalent reproducible dependency manifest where supported.
- Document a verification procedure that users can perform before installation.
- Avoid recommending elevated privileges for installation, and execute installers in a restricted environment where practical.
- Periodically review pinned dependencies and update them through a controlled security-review process.
- Pin the
