T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Third-Party CLI Is Installed and Executed Without Project-Level Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5 and 54-62; mirrored inSKILL-cn.md, lines 5 and 54-62
Vulnerability Type: Supply-chain dependency execution without cryptographic integrity verification
Risk Level: MediumComplete Code Snippet
From
SKILL.md:yaml metadata: {"clawdbot":{"emoji":"🤖","requires":{"bins":["npm","npx"]},"install":"npm install -g @dlazy/cli@1.0.9","installAlternative":"npx @dlazy/cli@1.0.9","homepage":"https://github.com/dlazyai/cli","source":"https://github.com/dlazyai/cli","author":"dlazyai","license":"see-repo","npm":"https://www.npmjs.com/package/@dlazy/cli","configLocation":"~/.dlazy/config.json","apiEndpoints":["api.dlazy.com","files.dlazy.com"]},"openclaw":{"systemPrompt":"When invoking this skill, use dlazy wan2.6-r2v-flash -h for help."}}bash npx @dlazy/cli@1.0.9 <command>text Or, if you prefer a global install, the skill's `metadata.clawdbot.install` field declares the exact pinned version (`npm install -g @dlazy/cli@1.0.9`). Review the GitHub source before installing.The same dependency installation behavior appears in
SKILL-cn.md.Technical Analysis
The skill contains no locally auditable implementation and delegates its functionality to the externally distributed
@dlazy/clinpm package. Although the package version is pinned to1.0.9, the project does not include a lockfile, expected package digest, vendored artifact, signature verification procedure, or reproducible mapping between the reviewed GitHub source and the npm archive that is executed.Both documented installation mechanisms execute package-controlled code:
npx @dlazy/cli@1.0.9downloads and executes the npm artifact.npm install -g @dlazy/cli@1.0.9installs it globally and may execute npm lifecycle scripts.
Version pinning protects against automatic upgrades but does not independently establish the integrity or provenance of the na ...[truncated 2295 chars]
- Remediation
View remediation
Remediation Suggestions
- Distribute a reviewed implementation with the skill or vendor the exact CLI artifact so the executable code is included in the audit scope.
- Publish and verify a cryptographic SHA-256 digest or signed provenance attestation for the expected npm package archive before installation or execution.
- Include a lockfile with integrity entries for the complete transitive dependency graph and install using a deterministic mechanism such as
npm ci. - Verify that the npm archive corresponds to a signed source tag and reproducible build from the referenced GitHub repository.
- Avoid global installation. Run the dependency in an isolated, unprivileged container or sandbox with a read-only filesystem and narrowly scoped access to required media files.
- Never run the installation as root or administrator. Explicitly document this restriction.
- Disable npm lifecycle scripts where they are unnecessary, for example by using
--ignore-scripts, after confirming that the CLI functions correctly without them. - Restrict network egress to the documented API endpoints and prevent access to unrelated credentials, home-directory files, SSH material, and cloud metadata endpoints.
- Use a short-lived, least-privilege API credential rather than exposing a long-lived organization key to the CLI process.
- Add automated dependency scanning, publisher monitoring, provenance verification, and periodic review of the package and its transitive dependencies.
