T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned npx Package Execution Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:17
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code Snippet:
yaml install: "npx clawhub install howtousehumans/debt-survival"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity hash. Depending on the local npm environment,npxcan retrieve and execute the package version currently resolved by the configured package registry.The project contains no lockfile, vendored installer, checksum, signature verification instructions, or other mechanism that binds installation to a previously audited release. Consequently, the code executed during installation can change independently of the reviewed
SKILL.mdfile.This is a supply-chain weakness rather than evidence that the current
clawhubpackage is malicious.Attack Path
- An attacker compromises the package registry account, publishing pipeline, package namespace, or another component involved in resolving the unpinned
clawhubpackage. - The attacker publishes a malicious or compromised release that is selected by
npx. - A user follows the documented installation command.
npxdownloads and executes the selected package.- Malicious package lifecycle or CLI code runs with the privileges of the user performing the installation.
Impact Assessment
Successful exploitation could execute arbitrary code under the installing user's account. Depending on that account's permissions, the payload could read or modify user-accessible files, access environment variables and credentials, make network requests, or install additional software. The reviewed project does not itself request elevated operating-system privileges, so administrative compromise is not established unless the user runs the command with elevated privileges.
- An attacker compromises the package registry account, publishing pipeline, package namespace, or another component involved in resolving the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the installer to a specific audited version, for example by using
npx clawhub@<exact-version>. - Use a lockfile or equivalent immutable dependency-resolution mechanism.
- Verify the downloaded package using a trusted signature or published integrity digest.
- Avoid automatically accepting a mutable registry release during installation.
- Document the expected package publisher, version, checksum, and trusted registry.
- Review package lifecycle scripts and transitive dependencies before updating the pinned version.
- Run installation with an unprivileged account and, where practical, inside a restricted environment.
- Pin the installer to a specific audited version, for example by using
