T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Third-Party Package Download and Execution
- Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-search npx -y socialdatax-skills@latest kuaishou search \ --keyword "" --pages 3 --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-search ``` The troubleshooting instructions also state: ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill instructs the Agent to run `socialdatax-skills@latest` through `npx -y`. The `@latest` version selector allows the retrieved package to change after the Skill has been reviewed, while `-y` suppresses the normal installation confirmation. The additional instruction to install or restore dependencies automatically increases the likelihood that remotely supplied code will be executed without meaningful user review. The project contains no copy of the npm package source, pinned package version, lockfile, integrity hash, or signature. Consequently, the effective code executed by this Skill cannot be verified from the audited artifact. This is a supply-chain risk rather than evidence that the current package is malicious. Exploitation would require compromise or malicious publication of the package or one of its transitive dependencies. ### Attack Path 1. An attacker compromises the npm publisher account, package release process, registry resolution path, or a transitive dependency. 2. The attacker publishes a malicious release that becomes the version selected by `socialdatax-skills@latest`. 3. A user requests Kuaishou research and the Agent follows the documented `npx ...[truncated 1416 chars]- Remediation
View remediation
