T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned npm Package Download and Execution
- Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-search \ --keyword "" --pages 3 --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-info \ --user-id "" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-profile npx -y socialdatax-skills@latest kuaishou user-info \ --profile-url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-creator-profile ``` The metadata also declares the same package without an exact version: ```yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"👤","homepage":"https://socialdatax.com/ai?from=clawhub"}} ``` ### Technical Analysis The documented commands use `npx -y socialdatax-skills@latest`. The `@latest` tag resolves dynamically to whichever release is currently designated as latest in the npm registry. Consequently, the code that will execute can change after this Skill has been reviewed, without any corresponding modification to `SKILL.md`. The `-y` flag automatically accepts package installation, removing an interactive confirmation that could otherwise alert the operator to a new download. No exact ...[truncated 2365 chars]- Remediation
View remediation
... ``` Do not use a range, tag, or floating version. 2. Maintain a lockfile and verify the package artifact against an approved integrity hash. Retrieve dependencies from a trusted registry with controlled configuration. 3. Remove automatic acceptance through `-y` where interactive operation is possible. In automated environments, enforce dependency approval through policy rather than accepting arbitrary new releases. 4. Install the reviewed dependency during a controlled build or provisioning phase instead of downloading executable code each time the Skill runs. 5. Execute the CLI in a sandbox with: - Only `SOCIALDATAX_API_KEY` exposed to the process. - No unrelated environment variables. - Read-only or narrowly scoped filesystem access. - Restricted subprocess capabilities. - An outbound network allowlist limited to documented SocialDataX endpoints and the minimum required package infrastructure during controlled installation. 6. Separate package installation from API execution so runtime environments do not need npm registry access. 7. Review each dependency update before changing the pinned version, including package contents, installation scripts, transitive dependencies, publisher provenance, and required network destinations. 8. Rotate `SOCIALDATAX_API_KEY` and investigate API activity if an untrusted package version has already been executed. ]]>
