T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Execution of an Unpinned Remote npm Package
- Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-creator-videos npx -y socialdatax-skills@latest kuaishou user-posts \ --profile-url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-creator-videos ``` Related directives include: ```yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"🗂️","homepage":"https://socialdatax.com/ai?from=clawhub"}} ``` ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill instructs the Agent to use `npx -y socialdatax-skills@latest`. The `@latest` version selector is mutable and does not bind execution to the specific package release that was reviewed. The `-y` option also suppresses the normal installation confirmation. Consequently, the effective executable code is downloaded at invocation time and may differ from the code available when the Skill was audited. No lockfile, exact version constraint, integrity hash, bundled implementation, or other mechanism is provided to verify the downloaded package. The instruction to install or restore dependencies automatically further reduces user oversight. The package executes as a local Node.js process under the Agent's operating-system identity. It is expected to receive `SOCIALDATAX_API_KEY`, creator identifiers or profile-share data, and pagination tokens ...[truncated 2940 chars]- Remediation
View remediation
