T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Third-Party CLI Execution Through npx
- Content
View full analysis
**Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only. > `npx clawhub@latest install deepseekoracle/lygo-champion-council` ``` ### Technical Analysis The migration instructions recommend running `npx clawhub@latest`. The `@latest` tag is mutable and can resolve to a different package release each time the command is invoked. No exact version, package integrity digest, lockfile, or other immutable identifier constrains the code retrieved and executed. `npx` may download the selected package and execute its command-line entry point. Consequently, the effective executable code is outside the audited project and can change after this Skill has been reviewed. The successor Skill installed by the command is also not part of the audited artifact. This is not automatic execution by the local scripts; exploitation requires a user or agent to follow the documented migration command. ### Attack Path 1. An attacker compromises the npm package, its publisher account, its distribution process, or another component involved in resolving `clawhub@latest`. 2. The attacker publishes a malicious version and causes the `latest` tag to reference it. 3. A user follows the migration instructions in `SKILL.md`. 4. `npx` downloads and executes the attacker-controlled CLI package. 5. The malicious package performs actions with the permissions of the invoking user, potentially before or while installing the requested successor Skill. ### Impact Assessment A compromised CLI package could access any files, environment variables, network resources, and subprocess capabilities available to the invoking account. Depending on that account's privileges, possible effects include credential theft, arbitrary file modification, inst ...[truncated 247 chars]- Remediation
View remediation
