T08 · Insecure Dependencies
- Location
README.md:14- Finding
Unpinned Package Execution in Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 14-17
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
bash ## Installation npx clawhub install auto-model-routerTechnical Analysis
The documented installation command invokes
clawhubthroughnpxwithout specifying a package version or integrity value. If the package is not already available locally,npxcan retrieve and execute the currently resolved release from the configured npm registry.Because the project provides no lockfile, integrity hash, vendored executable, or pinned CLI version, the code executed during installation can differ from the code originally reviewed. This creates a supply-chain trust boundary outside the audited repository. Exploitation would require compromise, substitution, or malicious publication of the package resolved as
clawhub; the repository itself does not contain evidence that the current package is malicious.Attack Path
- An attacker compromises the npm account, package publication process, registry resolution, or another relevant distribution channel for the package resolved as
clawhub. - The attacker publishes or causes resolution to a malicious release containing lifecycle scripts or malicious CLI behavior.
- A user follows the installation command from
README.md. npxdownloads and executes the unpinned package.- The malicious package runs with the privileges and environment access of the user executing the command.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could read or modify accessible files, steal environment variables or developer credentials, alter local configuration, install additional payloads, or tamper with other projects.
The impact is normally limited to the ...[truncated 281 chars]
- An attacker compromises the npm account, package publication process, registry resolution, or another relevant distribution channel for the package resolved as
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed release, for example:
bash npx clawhub@<reviewed-version> install auto-model-router - Verify the selected release against an expected package integrity hash or signed provenance before execution.
- Document the authoritative package name, publisher, registry, and release source so users can detect typosquatting or registry substitution.
- Prefer installing a verified, pinned CLI separately and invoking that trusted local installation rather than allowing installation-time resolution of the latest release.
- Use lockfiles and reproducible dependency controls where the installation workflow permits them.
- In controlled environments, disable network package resolution during invocation and use a previously verified local package cache.
- Warn users not to execute the installation process with administrative privileges unless strictly required.
- Pin the CLI to a specifically reviewed release, for example:
