T08 · Insecure Dependencies
- Location
README_CN.md:20- Finding
Unpinned Third-Party Package Execution via npx
- Content
View full analysis
Vulnerability Details
File Location:
README_CN.md, line 20
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
bash npx clawhub install admapixTechnical Analysis
The installation command asks
npxto resolve and execute theclawhubpackage without specifying a reviewed version or verifying its integrity. Depending on the local npm configuration and cache state,npxmay download the package from the configured registry and immediately run its CLI code.The project provides no version pin, lockfile, integrity hash, or registry restriction for this command. Consequently, the code executed during installation can change after this Skill has been reviewed. This creates a supply-chain trust boundary outside the audited project.
The finding does not prove that the current
clawhubpackage is malicious. The vulnerability is that the documented installation process does not ensure that users execute the same reviewed package release.Attack Path
- An attacker compromises the package publisher, registry account, package distribution channel, or a future release of the package.
- The attacker publishes a malicious version under the package name resolved as
clawhub. - A user follows the installation command in
README_CN.md. npxresolves and downloads the attacker-controlled version.- The malicious package's CLI or lifecycle code executes with the privileges of the user running the command.
- That code can perform actions allowed by the user's operating-system account before or while pretending to install the Skill.
Impact Assessment
Successful exploitation could result in arbitrary local code execution with the installing user's privileges. Depending on those privileges and the host environment, the malicious package could access user-readable files and environment variables, modify user-owned configuration, install additi ...[truncated 301 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin
clawhubto a specific version that has been reviewed:bash npx --yes clawhub@<reviewed-version> install admapix -
Document the authoritative npm registry and package publisher so users can verify the package source.
-
Provide a published integrity hash, signed release, or equivalent provenance mechanism for the approved package artifact.
-
Review each version before updating the documented pin.
-
Prefer an already installed and trusted CLI where appropriate, and provide instructions for verifying its version before use.
-
Keep installation commands consistent across localized README files so all users receive the same hardened procedure.
-
