T08 · Insecure Dependencies
- Location
README.md:11- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 11-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
markdown ## Installation ```bash npx clawhub install auto-model-routertext ### Technical Analysis The documented installation procedure invokes `clawhub` through `npx` without specifying an exact package version. If the package is not already available locally, `npx` may retrieve it from the configured package registry and execute it immediately. Consequently, the installer code executed by users is not cryptographically or version-bound to the code that was reviewed. A compromised package registry, package-maintainer account, or malicious future `clawhub` release could change the effective installation behavior after this skill has passed review. This is a supply-chain weakness in the documented installation process. The audited artifact itself contains no malicious scripts or executable implementation. ### Attack Path 1. An attacker compromises the registry entry, maintainer account, publication token, or release process for the `clawhub` package. 2. The attacker publishes a malicious package version under the expected package name. 3. A user follows the installation command in `README.md`. 4. `npx` resolves the unpinned package to the attacker-controlled version. 5. The malicious package executes during installation with the privileges and environment of the user running the command. 6. It may access any files, credentials, tokens, or other resources available to that user. This path depends on compromise or malicious control of the external package supply chain; no such compromise is demonstrated within the audited project. ### Impact Assessment Successful exploitation could result in arbitrary code execution under the installing user's account. The potential scope includes reading or modifying user-accessible files, ste ...[truncated 410 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the installer to an exact, reviewed version, for example:
bash npx --yes clawhub@<reviewed-exact-version> install auto-model-router - Publish and document the expected package source, version, and integrity digest.
- Use lockfiles and registry integrity verification where the installation workflow supports them.
- Prefer a trusted, locally installed CLI whose version and checksum have been verified before execution.
- Run installation with a non-privileged account and a minimal environment that does not expose unrelated credentials.
- Establish release signing and package-publication protections, including multi-factor authentication and narrowly scoped publication tokens.
- Pin the installer to an exact, reviewed version, for example:
