T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Package Execution Through npx Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16
Vulnerability Type: Supply-chain exposure through an unpinned executable dependency
Risk Level: MediumVulnerable Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install howtousehumans/childcare-essentials"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying a fixed package version or verifying package integrity. Depending on the local environment andnpxbehavior, the command can download and execute the currently published version of the CLI package from its configured package registry.Because the executable dependency is not pinned to an audited version, the code executed at installation time may differ from the code that was reviewed. This creates a supply-chain trust boundary in which a compromised maintainer account, registry package, release process, or dependency could introduce arbitrary behavior after the Skill itself has been audited.
The finding does not establish that the current
clawhubpackage is malicious. The vulnerability is the installation process's reliance on mutable, unverified third-party executable content.Attack Path
- An attacker compromises the package publisher, registry entry, release pipeline, or a transitive dependency associated with the unpinned
clawhubCLI. - The attacker publishes a modified package version containing malicious installation or runtime behavior.
- A user follows the documented installation procedure.
npxresolves and downloads the attacker-controlled or compromised package version.- The downloaded package executes with the operating-system permissions of the user running the installation command.
- The malicious package can perform any action permitted to that user, independently of the reviewed contents of
SKILL.md.
Impact Assessment
Successful exploitation could ...[truncated 508 chars]
- An attacker compromises the package publisher, registry entry, release pipeline, or a transitive dependency associated with the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the installer CLI to a specifically reviewed version, for example by using an explicit version in the
npxpackage specification. - Pin the Skill package to an immutable release, commit identifier, or cryptographic digest where the package manager supports it.
- Use a lockfile and registry integrity metadata so unexpected package changes cause installation to fail.
- Run installation in a sandbox or low-privilege environment with no sensitive credentials available.
- Configure an approved package registry and verify package provenance, signatures, and publisher identity.
- Review both direct and transitive dependencies whenever the pinned version is intentionally updated.
- Pin the installer CLI to a specifically reviewed version, for example by using an explicit version in the
