T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
yaml install: "npx clawhub install howtousehumans/dance-movement"Technical Analysis
The installation command invokes the
clawhubnpm package throughnpxwithout specifying a version or integrity constraint. If the package is not already available locally,npxcan retrieve and execute the version currently resolved by the configured npm registry.Consequently, the executable used during installation may differ from the version reviewed when this skill was published. Compromise of the package, its publishing account, its dependency chain, or the configured registry could cause attacker-controlled code to execute during installation. The skill repository itself does not contain an embedded malicious script; the risk arises from executing an unpinned external dependency.
Attack Path
- An attacker compromises the
clawhubnpm package, a transitive dependency, its publisher account, or the package source resolved by the user's registry. - The attacker publishes a malicious version that includes install-time or CLI-execution code.
- A user or automation system runs:
bash npx clawhub install howtousehumans/dance-movement - Because no package version or integrity value is specified,
npxresolves and downloads the attacker-controlled release. npxexecutes the downloaded CLI under the privileges and environment of the installing user.- The malicious process can perform any operation permitted to that user, including accessing readable files, modifying writable files, using available credentials, and making network requests.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the account running the installation command. The affected scope can include ...[truncated 461 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version:
bash npx --yes clawhub@<reviewed-version> install howtousehumans/dance-movement - Record and verify the package integrity hash through a lockfile or an equivalent trusted dependency-verification mechanism.
- Configure npm to use an explicitly trusted registry and protect publisher accounts with strong authentication and restricted release permissions.
- Prefer installing the reviewed CLI as a locked project dependency and invoking its local binary rather than allowing
npxto download an implicitly selected release at execution time. - Run installation with a minimally privileged account in a sandbox or container that has no unnecessary credentials, sensitive filesystem access, or unrestricted network access.
- Review updates before changing the pinned version, including the package provenance, dependency changes, and published integrity metadata.
- Pin the CLI to a specifically reviewed version:
