T08 · Insecure Dependencies
- Location
README.md:19- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 19–23
Vulnerability Type: Supply-chain risk caused by unpinned package execution
Risk Level: MediumVulnerable Code
markdown ## Install ```bash npx clawhub install admapixtext The same installation instruction is duplicated in `README_CN.md`, lines 19–23. ### Technical Analysis The documented installation command invokes `clawhub` through `npx` without specifying a package version or integrity constraint. If the package is not already available in a trusted local cache, `npx` can retrieve the current package release from its configured registry and execute it with the installing user's permissions. Because the resolved package may change after this Skill has been audited, the effective installation code is not reproducible or bounded to the reviewed repository contents. Registry-account compromise, a malicious future release, dependency compromise, or registry configuration manipulation could therefore introduce arbitrary executable behavior. ### Attack Path 1. An attacker compromises the publisher account, package distribution channel, or a transitive dependency used by the unpinned `clawhub` release. 2. The attacker publishes a malicious version or causes dependency resolution to select malicious code. 3. A user follows the documented command: `npx clawhub install admapix`. 4. `npx` resolves and downloads the attacker-controlled package version. 5. The package CLI or applicable lifecycle code executes under the user's account. 6. The malicious code can access resources available to that account, subject to operating-system and sandbox restrictions. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the user running the installation command. Potential scope includes reading or modifying user-accessible files, accessing environment variables and locally available c ...[truncated 271 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specifically reviewed version:bash npx clawhub@<verified-version> install admapix - Use an exact version rather than a floating tag or range.
- Document the expected package registry and publisher identity.
- Where supported, verify package provenance, signatures, and integrity hashes before execution.
- Review and lock transitive dependencies associated with the selected installer version.
- Apply the same corrected command to
README_CN.md. - Prefer an installation workflow that separates package download and verification from execution.
- Pin
