T08 · Insecure Dependencies
- Location
SKILL.md:32- Finding
Unpinned Third-Party Package Execution in Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:32-34; duplicated inREADME.md:10-14
Vulnerability Type: Supply-chain risk from unpinned package execution
Risk Level: MediumComplete vulnerable code snippets:
SKILL.md:32-34bash ## Install ```bash npx skills add blammectrappora/noir-photo-generatortext `README.md:10-14` ```bash Via ClawHub/OpenClaw: ```bash npx skills add blammectrappora/noir-photo-generatortext ### Technical Analysis The documented installation command invokes `npx` with the unversioned `skills` package. If that package is not already installed, `npx` can retrieve it from the configured npm registry and execute its CLI. No exact version, integrity hash, lockfile, or other immutable artifact reference constrains the code that will run. Consequently, the effective installer can change after this skill has been reviewed. Compromise of the package, its maintainer account, its dependencies, or the configured package registry could cause later installations to execute code different from the reviewed implementation. This finding does not establish that the current `skills` package is malicious. It identifies an unsafe supply-chain boundary in which mutable third-party code is downloaded and executed. ### Attack Path 1. An attacker compromises the npm package, a maintainer account, a transitive dependency, or the registry resolution path for `skills`. 2. The attacker publishes a malicious release under the package version selected by default. 3. A user follows the documented `npx skills add ...` installation command. 4. `npx` downloads and runs the attacker-controlled package code. 5. That code executes with the privileges of the user running the installation command. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that account's permissions, the malicious ins ...[truncated 325 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the installer package to a specifically reviewed version, for example by using an exact version rather than an unversioned package name.
- Verify the selected package source and publisher before recommending it to users.
- Where supported, enforce package integrity through a lockfile, checksum, signature, or immutable artifact reference.
- Prefer an official installer that does not dynamically execute mutable registry code.
- Document the expected package version and update it only after reviewing the new release and its dependency tree.
- Apply the same corrected installation instructions in both
SKILL.mdandREADME.md. - Advise users not to run installation commands with administrative privileges unless strictly required.
