T08 · Insecure Dependencies
- Location
SKILL.md:8- Finding
Unpinned Third-Party Package Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8-9
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
markdown > **Consolidated (Δ9 v2):** New installs → `lygo-champion-council`. This slug is legacy retention only. > `npx clawhub@latest install deepseekoracle/lygo-champion-council`Technical Analysis
The documented migration command instructs users to invoke
clawhubthroughnpxwith the mutable@latestversion selector. If the package is not already available locally,npxmay retrieve and execute package code from the configured npm registry. The exact code executed can therefore change after this skill has been reviewed.The command also installs the external
deepseekoracle/lygo-champion-councilskill, whose contents are not included in this repository and were outside the audit scope. Neither the executable package version nor the successor artifact is pinned to an audited version or cryptographic digest.This creates a supply-chain trust boundary in which package-publisher compromise, registry compromise, malicious future releases, or compromise of the externally installed skill could turn a legitimate-looking migration instruction into arbitrary code execution or unsafe agent behavior.
Attack Path
- An attacker compromises the
clawhubpackage publisher, distribution channel, or a future release resolved by thelatesttag. Alternatively, the externally hosted successor skill is compromised. - A user follows the migration command in
SKILL.md. npxresolves and downloads the package currently referenced byclawhub@latest.- The downloaded package executes with the invoking user's operating-system privileges.
- The compromised package can perform arbitrary actions available to that account, or install attacker-controlled successor skill content.
- The installed content may continue affecting later invocations i ...[truncated 720 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
clawhub@latestwith an explicitly pinned, reviewed version. - Verify the downloaded package against a trusted lockfile or cryptographic integrity digest before execution.
- Pin the successor skill to an immutable release identifier and integrity hash rather than a mutable name or channel.
- Document the expected package registry, publisher identity, package version, and digest so users can validate provenance.
- Prefer a non-executing download-and-review workflow: retrieve the package, inspect its scripts and successor content, verify integrity, and only then execute installation.
- Run installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and constrained network access.
- Avoid lifecycle scripts where possible, or explicitly disable them during package retrieval and enable execution only after review.
- Maintain an audited upgrade process so any version or digest change triggers a new security review.
- Replace
