T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned npm Package Is Downloaded and Executed Without Confirmation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:25-27(the same pattern recurs at lines 29-92; related unversioned installation metadata appears at line 7, and automatic dependency restoration is encouraged at line 130)
Vulnerability Type:T08: Insecure Dependencies
Risk Level: HighVulnerable Code:
bash npx -y socialdatax-skills@latest kuaishou hot-search \ --pretty --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishouRelated configuration and instructions:
yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"⚡","homepage":"https://socialdatax.com/ai?from=clawhub"}}text If the current environment has permission, install or restore automatically.Technical Analysis
The Skill repeatedly invokes
socialdatax-skills@latestthroughnpx -y. Thelatestnpm tag is mutable and can resolve to a different package version after the Skill has been reviewed. The-yoption suppresses the normal installation confirmation, causing the resolved package to be downloaded and executed automatically.The package implementation is not included in the audited project, so its behavior, network access, credential handling, and installation lifecycle scripts cannot be verified from this artifact. The metadata also specifies the package without an exact version, while the troubleshooting instructions encourage automatic installation or restoration.
This creates a supply-chain execution path in which code that was not present during the audit can run with the Agent's operating-system permissions. Exploitation would require compromise of the package, its maintainer account, the npm distribution path, or another mechanism that causes the package name or mutable tag to resolve to malicious c ...[truncated 1639 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
socialdatax-skills@latestwith an audited, exact package version, for examplesocialdatax-skills@X.Y.Z. - Pin the dependency in
package.jsonand commit a lockfile containing integrity hashes rather than downloading a mutable release for every operation. - Use
npm ci --ignore-scriptswhere package lifecycle scripts are unnecessary. If scripts are required, review and explicitly authorize them. - Remove
-yfrom ad hoc remote package execution or require explicit approval before downloading and executing a previously unavailable version. - Add an exact version to the Skill installation metadata instead of using an unversioned package reference.
- Do not automatically restore dependencies without verifying the expected version, integrity hash, registry, and package provenance.
- Configure npm to use a trusted registry and enable provenance or signature verification where supported.
- Run the CLI in a restricted environment with minimal filesystem access, limited outbound network access, and only the required API key exposed.
- Establish an update process in which new dependency versions are reviewed, tested, and deliberately pinned before deployment.
- Replace
