T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution in Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code:
yaml install: "npx clawhub install howtousehumans/fermentation-food-preservation"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying a reviewed package version or integrity digest. If the package is not already available locally,npxcan retrieve it from the configured package registry and execute it with the installing user's privileges.Because the package version is not pinned, the code executed during installation can differ from the version assessed when this Skill was reviewed. Compromise of the package, its registry account, or a transitive dependency could therefore introduce attacker-controlled code without requiring any change to
SKILL.md.Attack Path
- An attacker compromises the
clawhubpackage, its publisher account, or an unpinned dependency used by the package. - The attacker publishes a malicious version under the package name resolved by
npx. - A user follows the documented installation command.
npxdownloads the current package version from the configured registry.- Attacker-controlled CLI, lifecycle, or dependency code executes under the user's account.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user running the installation command. Depending on that user's permissions, the malicious package could access local files and credentials, alter user-level configuration, install persistence, or make network requests.
The reviewed Skill does not itself contain such a payload; the risk arises from mutable, unpinned supply-chain content.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version rather than allowingnpxto resolve the latest release. - Verify package provenance and integrity through registry checksums, signed attestations, or an approved lockfile where supported.
- Prefer a trusted, preinstalled CLI when available.
- Disable or carefully review dependency lifecycle scripts during installation.
- Reassess the pinned package and its dependency tree before upgrading.
Example hardened form:
yaml install: "npx --yes clawhub@<reviewed-version> install howtousehumans/fermentation-food-preservation"- Pin
