T08 · Insecure Dependencies
- Location
README.md:17- Finding
Unpinned Global Installation of a Third-Party CLI Package
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 17–20
Vulnerability Type: Supply-chain exposure through a mutable dependency
Risk Level: MediumVulnerable Code
bash # Install CLI npm install -g clawdbot@latestTechnical Analysis
The publishing instructions direct users to install the mutable
latestrelease of the third-party npm packageclawdbotglobally. The project does not pin an audited version, provide an integrity hash or lockfile, or document a provenance-verification procedure.Because npm packages can execute lifecycle scripts during installation, a future compromised or malicious release selected by the
latesttag could execute code on the user's machine. Global installation also increases the affected scope compared with an isolated, project-local dependency.The instructions subsequently invoke the
clawhubcommand even though the installed package is namedclawdbot. This may be legitimate, but the package-to-executable relationship is not documented, making it harder for users to verify that the expected package supplies the command.Attack Path
- An attacker compromises the
clawdbotnpm publisher account, package repository, release pipeline, or one of its transitive dependencies. - The attacker publishes a malicious package version and assigns it the mutable
latestdistribution tag. - A user follows the documented command:
bash npm install -g clawdbot@latest - npm downloads the attacker-controlled release and may execute its lifecycle scripts during installation.
- Malicious code executes with the privileges of the user running npm and can modify resources accessible to that account.
- The globally installed package or executable can remain available for later use until removed.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the installing user's privileges. The attacker could access or modify user-readable files, devel ...[truncated 463 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latesttag with an exact, reviewed package version:bash npm install -g clawdbot@1.2.3 - Verify the selected release's publisher identity, provenance, signatures, and integrity before recommending it.
- Document explicitly that the
clawdbotpackage supplies theclawhubexecutable, if that relationship is intentional. - Prefer a project-local, locked installation over a global installation where practical.
- Commit an appropriate lockfile when dependencies are managed as part of the project and enforce integrity checks in CI.
- Consider running the CLI through a restricted environment or container with only the permissions required for publishing.
- Review package lifecycle scripts and transitive dependencies before updating the pinned version.
- Replace the mutable
