T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6 and 27–35; related automatic-installation guidance at line 70
Vulnerability Type: Supply-chain risk caused by unpinned dependency retrieval and execution
Risk Level: MediumVulnerable Code
yaml metadata: {"openclaw":{"requires":{"env":["SOCIALDATAX_API_KEY"],"bins":["node","npm"]},"primaryEnv":"SOCIALDATAX_API_KEY","install":[{"kind":"node","package":"socialdatax-skills","bins":[]}],"emoji":"📄","homepage":"https://socialdatax.com/ai?from=clawhub"}}bash npx -y socialdatax-skills@latest weibo detail \ --post-id "<post_id>" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-weibo-detail npx -y socialdatax-skills@latest weibo detail \ --post-url "<weibo_post_url_or_share_text>" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-weibo-detailRelated automatic-installation guidance:
text If the current environment has permission, install or restore automatically.Technical Analysis
The skill instructs the agent to retrieve and execute
socialdatax-skills@latestthroughnpx -y. The@latestselector does not identify an immutable, reviewed package version, while-ysuppresses the normal installation confirmation. Consequently, the code executed during a future invocation can differ from the code that existed when this skill was audited.The npm package implementation and its transitive dependencies are not included in the reviewed project, which contains only
SKILL.md. The audit therefore cannot verify the external package's runtime behavior, network destinations, filesystem access, or handling ofSOCIALDATAX_API_KEY. The issue is an unsafe supply-chain configuration rather than proof that the current package version is malicious.Attack Path
- An attacker compromises the npm ...[truncated 1522 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
socialdatax-skills@latestwith an exact, reviewed version such associaldatax-skills@X.Y.Z. - Commit a lockfile and use a reproducible installation workflow that verifies package integrity. Where supported, validate the expected registry tarball checksum before execution.
- Remove
-yand automatic installation guidance, or require explicit user authorization before downloading and executing a package that is not already installed. - Review the pinned package and relevant transitive dependencies before deployment. Re-run that review deliberately when upgrading versions.
- Configure npm to use an explicitly trusted registry and consider package provenance or signature verification.
- Run the CLI in a sandbox with minimal filesystem access, restricted outbound networking, no elevated privileges, and only the required environment variable.
- Avoid passing unrelated secrets or environment variables to the subprocess. Construct a minimal environment containing only
SOCIALDATAX_API_KEYand essential runtime settings. - Prefer shipping auditable, versioned implementation source with the skill, or provide a maintained wrapper that enforces version, integrity, environment, and permission restrictions.
- Replace
