T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Execution via Mutable npm Tag
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 16–20
Vulnerability Type: Supply-chain risk from unpinned third-party package execution
Risk Level: MediumVulnerable Code
markdown If you have the `clawhub` CLI: ```bash npx clawhub@latest install project-agoratext ### Technical Analysis The documented installation command uses `npx` to download and execute the `clawhub` npm package identified by the mutable `latest` tag. Because no immutable version, integrity hash, lockfile, or signature verification is specified, the code executed by future users may differ from the version reviewed when this skill was published. An attacker who compromises the npm publisher account, package release process, registry resolution path, or a transitive dependency could publish malicious code under a release selected by `latest`. Following the documented command would then download and execute that code on the local machine. ### Attack Path 1. An attacker compromises the `clawhub` package publication process, its publisher account, or a dependency included by a future release. 2. The attacker publishes a malicious package version that becomes the target of the `latest` tag. 3. A user follows the installation command in `SKILL.md`. 4. `npx` retrieves the attacker-controlled release from the package registry. 5. The package CLI or associated lifecycle code executes with the privileges of the invoking user. 6. The malicious package can access resources available to that user, subject to operating-system controls. ### Impact Assessment Successful exploitation could result in arbitrary code execution with the invoking user's privileges. Depending on the local environment, exposed resources could include project files, writable user files, environment variables, authentication tokens, wallet-related secrets, and other credentials accessible to the process. The malicious package could also modify files or invoke network services within the user' ...[truncated 184 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace the mutable
latesttag with an explicitly reviewed, immutable package version, for example:bash npx clawhub@<reviewed-version> install project-agora -
Verify the selected package version's provenance, publisher identity, and registry integrity metadata before recommending execution.
-
Use lockfiles and integrity hashes where the installation workflow supports them.
-
Prefer a trusted installation mechanism that verifies cryptographic signatures or published checksums.
-
Review package lifecycle scripts and transitive dependencies before updating the pinned version.
-
Test installation in a sandbox or least-privileged environment, especially on systems containing wallet credentials or other sensitive secrets.
-
Document a controlled update process so the pinned version is changed only after security review.
-
