T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution in Installation Command
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill content is mainly clear-thinking guidance, but it asks for broad filesystem access and uses an unpinned npx installer that users should review before installing.
Review this before installing in an environment with sensitive files or credentials. Prefer a pinned, trusted installer version, and consider whether this skill really needs filesystem access for a reasoning-only workflow.
SKILL.md:15Unpinned Package Execution in Installation Command
The install command invokes npx clawhub without pinning a specific version, which makes the supply chain nondeterministic and allows a compromised or newly published package version to be executed at install time. Because npx may fetch and run code directly, this creates a real risk of remote code execution if the upstream package or dependency chain is hijacked.
The condition "user asks whether a claim is true or presents conflicting information" is ambiguous and expansive enough to overlap with many ordinary conversations, with no clear boundary for what kinds of claims or contexts should invoke the skill. The trigger list also provides no negative examples or exclusion conditions to narrow activation.
The phrase "user describes being unable to make a decision or overthinking" is broad and could apply to a wide range of everyday user statements without distinguishing serious decision-support scenarios from casual indecision. The manifest does not provide constraints or negative examples to clarify scope.
No suspicious patterns detected.