T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unverified Third-Party CLI Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5 and 60; duplicated inSKILL-cn.md, lines 5 and 60
Vulnerability Type: Third-party dependency and supply-chain risk
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"🤖","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.0.9","installAlternative":"npx @dlazy/cli@1.0.9","homepage":"https://github.com/dlazyai/cli","source":"https://github.com/dlazyai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"When invoking this skill, use dlazy recraft-v3-svg -h for help."}}bash npx @dlazy/cli@1.0.9 <command>Technical Analysis
The Skill does not include the executable implementation used to perform its primary operation. Instead, it instructs the environment to retrieve and execute
@dlazy/cli@1.0.9from the npm registry, either through a global installation or an on-demandnpxinvocation.Pinning the package to version
1.0.9limits ordinary version drift, but the Skill provides no package integrity digest, vendored artifact, lockfile, signed provenance, or reproducible-build verification. The referenced GitHub repository therefore does not, by itself, prove that the npm artifact fetched during execution is identical to the reviewed source.npm package installation can execute package code and lifecycle scripts with the permissions of the invoking user. The global installation option also persists an executable outside the Skill directory. No evidence in the reviewed files establishes that the named package is currently malicious; the finding concerns the unverified remote dependency and the resulting supply-chain trust boundary.
Attack Path
- An attacker compromises the npm publisher account, registry delivery path, o ...[truncated 1336 chars]
- Remediation
View remediation
Remediation Suggestions
- Bundle a locally auditable implementation or a verified package artifact with the Skill rather than downloading executable code during use.
- Publish and enforce a cryptographic integrity digest for the exact npm tarball. Verify it before installation or execution.
- Provide signed release provenance and reproducible-build instructions that allow users to confirm that the npm artifact matches the referenced source revision.
- Use a lockfile and an explicitly trusted registry URL, and verify the integrity of all transitive dependencies.
- Prefer an isolated, non-global installation to prevent persistent modification of the user's executable environment.
- Disable npm lifecycle scripts where compatible, such as by using
--ignore-scripts, and explicitly document any scripts that are required. - Execute the CLI in a sandbox with narrowly scoped filesystem and network access. Only mount files deliberately selected by the user.
- Store API credentials using an operating-system credential manager where possible, apply least-privilege API scopes, and support prompt rotation and revocation.
- Apply the same hardened installation instructions consistently to both
SKILL.mdandSKILL-cn.md.
