T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 14
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
yaml install: "npx clawhub install howtousehumans/grow-food-anywhere"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact, audited package version or an integrity constraint. If the package is not already available locally,npxmay retrieve it from the configured package registry and execute its CLI or package lifecycle code.Because the referenced package version is mutable from the perspective of this project, the code executed during installation can change after the Skill has been reviewed. Security therefore depends on the continuing integrity of the package registry, the package publisher account, package resolution settings, and all transitive dependencies.
Attack Path
- An attacker compromises the
clawhubpackage, its publisher account, a resolved dependency, or the package source used by the victim. - The attacker publishes a malicious version containing hostile CLI or lifecycle code.
- A user runs the documented
npx clawhub install howtousehumans/grow-food-anywherecommand. npxresolves and downloads the mutable package version from the configured registry.- The malicious package code executes with the permissions of the user running the installation command.
Impact Assessment
Successful exploitation could allow arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the malicious package could read or modify accessible files, access user-level credentials and environment variables, alter installed Skill content, invoke network resources, or execute additional processes.
The command does not itself request elevated privileges, so direct impact is normally limited to the current user's privile ...[truncated 132 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a reviewed exact version, for example:bash npx --yes clawhub@<audited-exact-version> install howtousehumans/grow-food-anywhere - Prefer a lockfile-backed installation workflow that records exact dependency and transitive dependency versions.
- Verify package provenance and integrity through trusted registry metadata, checksums, signatures, or package-manager integrity fields before execution.
- Review the pinned package's CLI entry point and lifecycle scripts before approving it for use.
- Use a trusted registry explicitly and prevent dependency resolution from unapproved registries.
- Run installation with an unprivileged account in a restricted environment that does not expose unrelated credentials or sensitive files.
- Establish a controlled update process in which newer versions are reviewed and tested before changing the pinned version.
- Pin
