T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: MediumVulnerable Code:
yaml install: "npx clawhub install howtousehumans/anxiety-emergency"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an audited package version or integrity digest. When the package is not already available locally,npxcan retrieve executable package content from the configured package registry. Because the resolved version is mutable, the code executed at installation time may differ from the code available when this skill was reviewed.This creates a supply-chain trust boundary: compromise of the package publisher, registry account, package contents, or dependency resolution path could turn the documented installation command into a code-execution vector. The audited project itself contains no embedded malicious script, so exploitation depends on compromise or unexpected modification of the external package source.
Attack Path
- An attacker compromises the package publisher, registry account, package distribution channel, or a dependency resolved by the unpinned
clawhubpackage. - The attacker publishes a malicious or modified version that remains eligible for default
npxresolution. - A user runs the installation command from
SKILL.md. npxdownloads and executes the externally supplied package version.- Malicious package lifecycle or application code executes with the privileges of the user running the command.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, network resources, and other capabilities available to that account. Elevated system-level impact would require the command to be run with ...[truncated 68 chars]
- An attacker compromises the package publisher, registry account, package distribution channel, or a dependency resolved by the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version rather than relying on default registry resolution. - Use a lockfile where supported to pin transitive dependencies.
- Verify package integrity using a trusted digest, signature, or package provenance mechanism.
- Obtain the package only from an authenticated and approved registry.
- Review package lifecycle scripts and install behavior before deployment.
- Run installation as an unprivileged user in a sandbox or otherwise restricted environment.
- Establish an update process that requires security review before changing the pinned version.
- Pin
