T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumyaml install: "npx clawhub install howtousehumans/austerity-living"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact reviewed version or integrity digest. If the package is not already available locally,npxmay retrieve a mutable package release from the configured package registry and execute it with the privileges of the installing user.Because the effective
clawhubimplementation can change after this Skill has been reviewed, the audit does not fully constrain the code that will execute during installation. Compromise of the package publisher, registry account, publication pipeline, or package distribution channel could therefore introduce malicious behavior without modifyingSKILL.md.Attack Path
- An attacker compromises the
clawhubpackage publisher, release pipeline, registry account, or another relevant distribution component. - The attacker publishes a malicious package release under the package identity resolved by
npx clawhub. - A user runs the documented installation command.
npxresolves and downloads the mutable malicious release because no exact version or integrity value is specified.- Package lifecycle or command code executes locally with the installing user's privileges.
- The malicious release can access resources available to that user, subject to operating-system and runtime restrictions.
Impact Assessment
Successful exploitation could permit arbitrary code execution in the installing user's security context. Potentially exposed resources include files readable or writable by that user, environment variables, accessible credentials, and network services available from the host.
The command does not explicitly request elevated privileges, so administrative o ...[truncated 173 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed package version rather than allowingnpxto resolve the latest mutable release. - Use a lockfile and verified package integrity metadata where supported.
- Verify package provenance, publisher identity, signatures, and registry source before execution.
- Disable or carefully review dependency lifecycle scripts when they are not required.
- Execute installation in a sandbox or least-privileged environment without unnecessary credentials or sensitive filesystem access.
- Establish an update-review process so dependency upgrades are audited before the pinned version is changed.
- Pin
