T08 · Insecure Dependencies
- Location
SKILL_EN.md:40- Finding
Unpinned Third-Party Packages Can Execute Mutable Remote Code
- Content
View full analysis
Vulnerability Details
File Location:
SKILL_EN.md:40,SKILL_EN.md:131,SKILL_EN.md:275; mirrored commands appear inSKILL.md:38,SKILL.md:129, andSKILL.md:272
Vulnerability Type: Unpinned package installation and direct execution of the latest registry release
Risk Level: HighVulnerable Code Snippets
SKILL_EN.md:40:bash pip install clawlockSKILL_EN.md:131:bash pip install -U clawlockSKILL_EN.md:275:bash npm install -g promptfoo npx promptfoo@latestTechnical Analysis
The Skill directs the Agent to install or execute third-party packages without pinning an audited version or verifying an integrity hash. In particular,
npx promptfoo@latestresolves and executes whichever release the package registry currently identifies as the latest version.The actual
clawlockandpromptfooimplementations are not included in this project, so their installation scripts, dependency trees, and runtime behavior cannot be verified from the audited files. Although there is no evidence that the current upstream packages are malicious, these commands create a mutable supply-chain execution path: the code executed during a future Skill run may differ from the code that existed when the Skill was reviewed.Python and Node.js packages can execute code during installation or when their command-line entry points are invoked. Consequently, compromise of a publisher account, registry infrastructure, package dependency, or future release could turn these instructions into arbitrary local code execution.
Attack Path
- An attacker compromises an upstream publisher account, package registry, or transitive dependency, or causes a malicious future release to become the selected version.
- A user asks the Skill to perform a scan, update, or red-team operation.
- The Skill instructs the Agent to run
pip install clawlock,pip install -U clawlock, or `npx p ...[truncated 1101 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every executable package to a specifically reviewed version, such as
clawlock==2.5.0andpromptfoo@<reviewed-version>; do not use@latest. - Use lock files and require cryptographic integrity verification. For Python, install from a reviewed requirements file with exact versions and hashes using
pip install --require-hashes -r requirements.txt. - For Node.js, commit a reviewed lock file and use
npm ci; avoid directnpxexecution of packages that have not already been installed and verified. - Verify package provenance, publisher identity, release signatures, and expected checksums before installation or update.
- Require explicit user approval immediately before any package installation or upgrade, showing the exact package name, resolved version, source registry, and expected integrity value.
- Run optional red-team dependencies in an isolated environment with restricted filesystem access, sanitized environment variables, and limited network access.
- Do not automatically replace the local Skill file from a mutable branch. Retrieve a versioned release artifact or immutable commit and verify its digest before replacement.
- Document the reviewed versions in both
SKILL_EN.mdandSKILL.mdso the two language variants enforce the same dependency policy.
- Pin every executable package to a specifically reviewed version, such as
