T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Supply-chain dependency risk
Risk Level: MediumVulnerable Code
yaml metadata: openclaw: requires: tools: [filesystem] install: "npx clawhub install howtousehumans/body-mechanics-injury-prevention"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an audited package version or integrity digest. Depending on the local environment and package cache,npxcan retrieve the current package release from a configured registry and execute its CLI code.Consequently, the code executed during installation is not immutably tied to the version reviewed in this audit. A compromised package publisher, registry account, dependency, or later malicious release could alter installation behavior after the Skill has been approved.
The reviewed Skill does not itself contain a malicious payload. The vulnerability is the mutable, unverified supply-chain execution path created by the installation instruction.
Attack Path
- An attacker compromises the
clawhubpackage, one of its executable dependencies, its publisher account, or the package source used by the victim. - The attacker publishes a modified version containing malicious CLI or lifecycle behavior.
- A user follows the documented unpinned
npx clawhub install ...instruction. npxresolves and downloads the attacker-controlled release rather than a previously audited version.- The package executes with the operating-system privileges of the user running the installation command.
- The payload can access or modify resources available to that user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include user-readable files, writable project files, environment variables, developer credentials, and network resources available to that account. Adm ...[truncated 175 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, audited version rather than relying on the current registry release. - Verify the package using a cryptographic integrity digest or signed provenance before execution.
- Use a lockfile where supported and retain it with the reviewed Skill package.
- Configure installation to use an explicitly trusted registry.
- Disable or review dependency lifecycle scripts where operationally possible.
- Run installation as an unprivileged user in a sandbox with minimal filesystem, credential, and network access.
- Establish a controlled update process in which new package versions are reviewed before the pinned version is changed.
For example, use the platform-supported equivalent of:
text npx clawhub@<audited-version> install howtousehumans/body-mechanics-injury-preventionThe exact version should be accompanied by an integrity value and should only be updated after security review.
- Pin
