T08 · Insecure Dependencies
- Location
clawhub.json:55- Finding
Patch-Hash Mismatches Are Automatically Accepted by Default
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill needs Review because it describes installing and running a cryptocurrency node with default CPU mining, but the installer and security-critical scripts are missing and one default weakens its patch-integrity claims.
Install only after reviewing the complete package, including install.sh and all referenced scripts. Treat default mining as an explicit opt-in decision, set START_MINER=0 unless you intend to mine, and require strict patch-hash validation before building or running node software.
clawhub.json:55Patch-Hash Mismatches Are Automatically Accepted by Default
clawhub.json:7Declared Entrypoint and Security-Critical Scripts Are Missing from the Package
The manifest describes powerful actions such as install, build, verify, mine, and update, but it does not state clear operator prompts, safety gates, or invocation constraints. In an agent setting, broad capability descriptions can cause over-trusting automation or unintended execution of high-impact actions like software installation, node operation, and mining.
The skill enables CPU mining by default via START_MINER=1 while the manifest lacks a prominent warning that it may consume system resources and run sustained compute workloads. This is dangerous because users or agents may trigger installation expecting node setup only, but instead start resource-intensive mining that can degrade performance, increase power usage, or violate hosting policies.