T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13
Vulnerability Type: Supply-chain risk from unpinned, remotely retrieved executable dependencies
Risk Level: MediumVulnerable Code
yaml install: "npx clawhub install howtousehumans/budget-meal-prep"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact reviewed version or integrity hash. Depending on the local environment and package cache,npxcan retrieve executable package content from a remote registry at installation time.Because the retrieved package is mutable and is not cryptographically bound to the version reviewed during this audit, the code ultimately executed may differ from the audited skill content. A compromised registry account, malicious package release, or upstream supply-chain compromise could therefore cause the command to execute attacker-controlled package code.
The project does not provide a lockfile, checksum, signature-verification procedure, or other mechanism for validating the retrieved CLI package and installed skill artifact.
Attack Path
- An attacker compromises the package publishing account, distribution source, or another relevant upstream component.
- The attacker publishes a malicious release under the package name resolved by
npx, or replaces mutable skill content at the referenced source. - A user follows the installation instruction in
SKILL.md. npxresolves and downloads the current package content rather than a specifically reviewed and integrity-verified version.- Malicious CLI, lifecycle, or installation code executes with the privileges of the user running the command.
- That code can access resources available to the invoking account and may install modified skill content or alter local files.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user who runs the installation command. The resulting ...[truncated 511 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the installation CLI to an exact reviewed version, for example by using an explicit version rather than allowing
npxto resolve the latest release. - Pin the skill artifact itself to an immutable release, commit digest, or content hash where the package manager supports it.
- Publish and verify cryptographic checksums or signatures before executing downloaded components.
- Use a lockfile or equivalent dependency manifest to preserve the reviewed dependency graph.
- Disable or avoid dependency lifecycle scripts when they are not required.
- Prefer installing from an official, authenticated registry with protected publisher accounts and provenance attestations.
- Run installation with a nonprivileged account in a restricted environment, granting only the filesystem and network access necessary for installation.
- Document the expected package version, artifact digest, publisher identity, and verification procedure so users can confirm that the installed content matches the audited release.
- Pin the installation CLI to an exact reviewed version, for example by using an explicit version rather than allowing
