T08 · Insecure Dependencies
- Location
scripts/validate-skill.sh:91- Finding
Unpinned npm Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/validate-skill.sh:91-102; related instructions inSKILL.md:184-199anddistro/platforms/clawhub-publish.md:11-15
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash # Check clawhub CLI if command -v npx >/dev/null 2>&1; then echo "✅ npx available (clawhub CLI)" else echo "⚠️ npx unavailable; install Node.js" fi # Check login status if npx clawhub whoami >/dev/null 2>&1; then echo "✅ Logged in to ClawHub" else echo "⚠️ Not logged in to ClawHub; run: clawhub login" fiThe associated installation and publication instructions use:
bash npm install -g clawhub clawhub login npx clawhub --workdir . skill publish . \ --name "<skill-name>" \ --version "1.0.0" \ --changelog "Initial release"Technical Analysis
The Skill executes
clawhubthroughnpxwithout specifying an audited package version. If the package is not already installed locally,npxcan retrieve and execute package code from the configured npm registry. The documented global installation command also installs the latest package release without a version or integrity constraint.Consequently, the code that executes is not fixed to the version reviewed with this Skill. A compromised npm account, malicious replacement release, registry compromise, dependency compromise, or unexpected upstream update could alter the effective executable payload after the Skill has passed review.
The validation script makes this risk less apparent because a nominal login-status check can initiate third-party package resolution and execution. A validation operation should not implicitly install or execute mutable remote code.
Attack Path
- An attacker compromises the
clawhubpackage, one of its dependencies, or the package publication account, and publishes a malicious ...[truncated 1173 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to a reviewed version, for example:
bash npx --yes clawhub@<reviewed-version> whoami -
Prefer a preinstalled, verified executable during validation:
bash if command -v clawhub >/dev/null 2>&1; then clawhub whoami else echo "clawhub is not installed" fi -
Use
npx --no-installwhere supported so validation cannot download a missing package. -
Require explicit user approval before any dependency installation or remote package execution.
-
Pin transitive dependencies through a lockfile for locally managed installations.
-
Verify package provenance, checksums, signatures, and publisher identity before installation.
-
Run publishing tools in a constrained environment with minimal filesystem access and only the credentials needed for that publication.
-
Document the exact supported CLI version instead of recommending an unconstrained global installation.
-
