T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned External Package Execution Creates a Supply-Chain Risk
- Content
View full analysis
**Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only. > `npx clawhub@latest install deepseekoracle/lygo-champion-council` ``` ### Technical Analysis The installation instructions use the mutable `latest` tag for the externally supplied `clawhub` package and direct users to install a separately maintained Skill that is not included in the audited project. Because neither dependency is pinned to a reviewed immutable version, commit, package digest, or signature, the code retrieved when a user runs this command may differ from the code available when this Skill was audited. An attacker who compromises the package registry entry, publisher account, upstream repository, or successor Skill could replace the effective installation payload. The command is documented rather than automatically invoked by the included scripts, so exploitation requires a user or agent to follow the installation instruction. ### Attack Path 1. An attacker compromises the `clawhub` package, its publishing account, or the externally maintained successor Skill. 2. The attacker publishes a modified version under the mutable release referenced by `@latest`, or modifies the successor Skill fetched during installation. 3. A user or agent follows the documented `npx` command. 4. `npx` downloads and executes the currently published package rather than an immutable, previously reviewed version. 5. The compromised installer or installed Skill executes attacker-controlled behavior with the permissions of the invoking process. ### Impact Assessment Successful exploitation could allow arbitrary behavior supported by the downloaded installer or successor Skill under the invoking user's privileges. Depending on the external payload ...[truncated 422 chars]- Remediation
View remediation
