T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:20,48
Vulnerability Type: Unpinned npm/npx supply-chain dependency
Risk Level: MediumVulnerable Code:
text 1. **Skills(OpenClaw 用戶首選)** — `npx skills add okx/agent-skills`,一行搞掂text Run `npx skills add okx/agent-skills`, resolve any issues you encounter, then check the BTC price.Technical Analysis
The Skill directs the agent to retrieve and execute the current registry-resolved version of
okx/agent-skillsthroughnpx. It does not pin a reviewed version, verify a package digest or signature, or require inspection of the resolved package. Consequently, the code that executes can differ from the code present when this Skill was audited.The broad instruction to “resolve any issues you encounter” also gives the agent discretion while installing external code. Although this is not itself evidence of malicious behavior, it increases the consequences of unsafe package output or installation instructions.
Attack Path
- An attacker compromises the referenced package, its publisher account, or a transitive dependency.
- The attacker publishes a malicious release under the package reference used by the Skill.
- A user or agent follows the documented
npx skills add okx/agent-skillsinstruction. npxresolves and downloads the mutable package content.- Package or lifecycle code executes with the invoking user's privileges.
- The malicious code may read local files, modify the agent environment, or target subsequently configured OKX credentials.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's account. The accessible scope may include user-readable files, agent configuration, installed skills, and any OKX credentials stored in
~/.okx/config.toml. If exposed credentials have live trading permission, an attacker could submit or manipulate trades within the ...[truncated 161 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specific, reviewed release rather than resolving the latest available version.
- Verify package provenance, signatures, and integrity hashes before execution.
- Document the expected publisher, registry, version, and checksum.
- Review package lifecycle scripts and transitive dependencies before recommending installation.
- Prefer installation in a restricted or isolated environment without access to trading credentials.
- Configure credentials only after package validation is complete.
- Replace the open-ended instruction to resolve arbitrary installation issues with narrowly scoped, documented troubleshooting steps.
