T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Third-Party CLI Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: MediumVulnerable Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install howtousehumans/fishing-basics"Technical Analysis
The installation instruction invokes
clawhubthroughnpxwithout specifying an exact package version or verifying package integrity. If the package is not already available locally,npxmay retrieve and execute the currently published version from the configured package registry.Consequently, the code executed during installation is not fixed to the content reviewed in this project. A compromised maintainer account, malicious package release, registry compromise, or unexpected upstream update could alter the effective installation behavior after this Skill has been audited. The external CLI implementation and its lifecycle behavior are not included in the audited project, so they cannot be verified from the repository contents.
Attack Path
- An attacker compromises the publication process, maintainer account, registry entry, or another relevant component in the
clawhubpackage supply chain. - The attacker publishes a malicious version under the package name resolved by
npx. - A user or automation system follows the installation instruction in
SKILL.md. npxresolves and downloads the attacker-controlled package version because no exact version or integrity constraint is present.- The package's CLI entry point or applicable installation lifecycle code executes on the local system.
- The malicious package performs actions with the privileges and environmental access of the installing process.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the account performing the installation. The resulting scope may ...[truncated 480 chars]
- An attacker compromises the publication process, maintainer account, registry entry, or another relevant component in the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than resolving the latest available release, for example by using an explicit version supported by the installation environment. - Verify the downloaded package against a trusted integrity hash, signed release, or provenance attestation before execution.
- Restrict installation to an approved registry and enable registry namespace protections where available.
- Audit the pinned CLI package, including its dependencies and package lifecycle scripts.
- Run installation with the minimum necessary privileges in a sandbox or isolated environment without unrelated credentials.
- Use a lockfile or equivalent immutable dependency manifest when the surrounding installation system supports one.
- Prefer a trusted, preinstalled CLI binary so installation does not automatically download and execute mutable code.
- Pin
