T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution During Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
yaml install: "npx clawhub install hygiene-without-infrastructure"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout pinning an audited package version or specifying an integrity hash. Depending on the local package state and npm configuration,npxmay retrieve the current version of the package from a configured registry and execute its CLI or package lifecycle code.Because the dependency is mutable after the Skill has been reviewed, the effective installation behavior is not fully represented by the audited project contents. A compromised registry account, malicious replacement release, dependency confusion condition, or unexpected upstream update could therefore introduce arbitrary code into the installation process.
Attack Path
- An attacker compromises the package publisher, registry account, distribution channel, or another component involved in resolving the unpinned
clawhubpackage. - The attacker publishes a malicious or compromised version that contains harmful CLI or lifecycle code.
- A user follows the documented command:
shell npx clawhub install hygiene-without-infrastructure npxresolves and downloads the mutable package version from the configured registry.- The downloaded package executes with the permissions of the user running the installation command.
- The malicious package can access resources available to that user before or while installing the requested Skill.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on those privileges and the host environment, the compromised package could read or alter user-accessible files, obtain credentials exposed to the process, modify ...[truncated 436 chars]
- An attacker compromises the package publisher, registry account, distribution channel, or another component involved in resolving the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specifically reviewed version rather than relying on mutable registry resolution, for example:shell npx clawhub@<audited-version> install hygiene-without-infrastructure - Verify the selected package version and its transitive dependencies before publishing the installation instruction.
- Use a lockfile and registry-provided integrity metadata where the installation workflow supports them.
- Document the expected trusted registry and reject untrusted or unexpected package sources.
- Prefer a preinstalled, administratively managed CLI or a verified local binary over dynamically downloading and executing a package during installation.
- Run installation with the minimum necessary privileges and without unrelated credentials in the process environment.
- Periodically re-audit the pinned version before intentionally upgrading it.
- Pin
