T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Execution of an Unpinned Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:9
Vulnerability Type: Insecure third-party dependency execution
Risk Level: MediumVulnerable Code
markdown > **Install instead:** `npx clawhub@latest install deepseekoracle/lygo-file-integrity-checker`Technical Analysis
The installation instruction invokes
npxwith the mutablelatesttag. This causes the package manager to retrieve and execute a release ofclawhubthat was not included in the audited project. Neither a fixed package version nor an integrity digest constrains the code that will run.Consequently, the effective installer can change after this Skill has been reviewed. If the package registry, maintainer account, package publication process, or a future release is compromised, following the documented instruction could execute attacker-controlled package code.
The audited project itself does not contain malicious executable code. This finding concerns the supply-chain boundary created by the installation instruction.
Attack Path
- An attacker compromises the package publisher, registry distribution path, or release process for the referenced npm package.
- The attacker publishes a malicious release that resolves under
clawhub@latest. - A user follows the installation instruction in
SKILL.md. npxdownloads and executes the malicious package release.- The package runs with the permissions of the invoking user and may also install unreviewed Skill content.
Impact Assessment
Successful exploitation could execute arbitrary code within the invoking user's privilege boundary. Depending on that user's permissions and environment, the malicious package could read or modify accessible files, access environment variables and credentials available to the process, make network requests, or install additional untrusted content.
The project provides no evidence that the current external package is malicious, and no privilege escalation beyond the ...[truncated 55 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
clawhub@latestwith an explicitly reviewed and immutable package version. - Pin and verify the package using a trusted registry-provided integrity digest or an independently published cryptographic checksum.
- Document the expected package publisher and trusted registry so users can validate provenance before execution.
- Review the pinned package, its transitive dependencies, and installation lifecycle scripts.
- Prefer a lockfile-backed installation process using integrity metadata where practical.
- Avoid automatically executing remotely retrieved package code; provide a download-and-verify workflow before installation when possible.
- Replace
