T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Package Execution During Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 14
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
yaml install: "npx clawhub install howtousehumans/blue-collar-mental-health"Technical Analysis
The documented installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity hash. If the package is not already available locally,npxcan retrieve and execute the currently resolved version from the configured npm registry.Consequently, the code executed during installation is mutable and falls outside the reviewed artifact. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream change could cause arbitrary package CLI or lifecycle code to run when a user follows this instruction.
The finding is limited to the unpinned
npxdependency. The reviewed project itself contains onlySKILL.md; no embedded scripts, malicious payloads, persistence mechanisms, credential access, or data-exfiltration behavior were found.Attack Path
- An attacker compromises the upstream
clawhubpackage, its publisher account, or the package-distribution channel. - The attacker publishes a malicious version under the package name resolved by
npx. - A user follows the installation command from
SKILL.md. npxresolves and downloads the mutable package version.- The malicious package CLI or applicable lifecycle code executes with the privileges of the user running the command.
- That code can perform actions permitted to the installation process, potentially including reading user-accessible files, modifying local files, accessing available environment variables, or installing additional payloads.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope is bounded ...[truncated 508 chars]
- An attacker compromises the upstream
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than allowingnpxto resolve the latest release. - Use a lockfile or other immutable dependency manifest where the installation mechanism supports it.
- Verify package integrity using registry-provided integrity metadata, checksums, signatures, or provenance attestations.
- Retrieve dependencies only from an approved and authenticated registry.
- Review the resolved package, transitive dependencies, CLI entry point, and lifecycle scripts before execution.
- Prefer a download-and-verify workflow that separates package retrieval from execution.
- Run installation with the least-privileged account in a sandbox or isolated environment, without unnecessary credentials or sensitive environment variables.
- Disable dependency lifecycle scripts where feasible and not required.
- Document the expected publisher, version, checksum, and verification procedure alongside the installation command.
- Pin
