T08 · Insecure Dependencies
- Location
README.md:13- Finding
Unpinned Third-Party CLI Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 13–17
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
markdown ## Installation ```bash npx clawhub install auto-model-routertext ### Technical Analysis The documented installation procedure invokes the third-party `clawhub` npm package through `npx` without specifying a version, package integrity hash, trusted registry, or lockfile. When the package is not already available locally, `npx` may retrieve the currently resolved package release and execute its CLI code. Consequently, the code executed by users can differ from the code that was available when this Skill was audited. This creates a mutable supply-chain boundary outside the reviewed project. The project itself contains no malicious scripts or executable payloads. The risk arises from instructing users to execute an unpinned external package whose future contents cannot be established from this repository. ### Attack Path 1. An attacker compromises the npm account, publication pipeline, registry resolution, or another relevant distribution component for the `clawhub` package. 2. The attacker publishes a malicious or backdoored package release that satisfies unversioned resolution. 3. A user follows the installation instructions and runs: ```bash npx clawhub install auto-model-router ``` 4. `npx` resolves and downloads the attacker-controlled release. 5. The malicious CLI or applicable package lifecycle behavior executes with the privileges of the invoking user. ### Impact Assessment Successful exploitation could allow arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the malicious package could access user-readable files, modify user configuration, steal credentials available to the process, install additional components, or alter the Open ...[truncated 302 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the installer to a specifically reviewed release:
bash npx clawhub@<verified-version> install auto-model-router - Publish the expected npm registry, package identity, version, and integrity digest in the installation documentation.
- Prefer installing the CLI as a project dependency governed by a committed lockfile, then invoke the locked local binary.
- Disable or minimize package lifecycle scripts where the installation workflow supports doing so.
- Verify package provenance and signatures before execution, and document a trusted release-verification procedure.
- Run installation with least privilege in an isolated environment rather than from an administrator or root account.
- Periodically review and deliberately update the pinned version instead of automatically resolving the latest release.
- Pin the installer to a specifically reviewed release:
