T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned npm Installer Creates a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–13
Vulnerability Type: Unpinned third-party installer execution
Risk Level: MediumComplete Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install howtousehumans/cook-from-scratch"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an audited package version or integrity hash. If the package is not available locally,npxcan retrieve and execute the version currently resolved from the configured npm registry.Consequently, the executable code used during installation can change after this Skill has been audited. A compromise of the
clawhubnpm package, its publisher account, the dependency-resolution process, or the configured package registry could cause a future installation to execute code that was not present during this review. The Skill source does not provide a lockfile, checksum, signature, or other mechanism for verifying the installer artifact.The declared
filesystemtool requirement also appears unnecessary for the documented cooking-guidance workflow. Although the declaration alone does not demonstrate privilege escalation, removing unused capabilities would improve least-privilege compliance.Attack Path
- An attacker compromises the npm publisher account, package distribution channel, or another component controlling resolution of the unpinned
clawhubpackage. - The attacker publishes or causes resolution to a malicious package version.
- A user runs the documented command:
npx clawhub install howtousehumans/cook-from-scratch. npxretrieves the currently resolved package when it is not already available in the execution environment.- The downloaded package executes with the privileges of the user running the installer.
- Malicious installer code could access or modify data available to that user, s ...[truncated 761 chars]
- An attacker compromises the npm publisher account, package distribution channel, or another component controlling resolution of the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version rather than allowingnpxto resolve the current release:yaml install: "npx clawhub@<reviewed-version> install howtousehumans/cook-from-scratch" - Verify the selected package artifact using a trusted lockfile, registry integrity metadata, a cryptographic checksum, or a verified signature.
- Prefer a separately installed and centrally managed installer whose version is controlled by the deployment environment.
- Disable automatic acceptance of newly published versions and require security review before updating the pinned installer.
- Execute installation in a sandbox or restricted account without administrative privileges, sensitive environment variables, or unnecessary filesystem access.
- Remove the
filesystemtool requirement unless the Skill has a documented runtime need for filesystem operations. - Review both the installer and the referenced Skill package whenever either pinned version or verified artifact changes.
- Pin
