T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned npx Package Execution Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install mentorship"Technical Analysis
The installation instruction invokes
clawhubthroughnpxwithout specifying a package version or integrity constraint. If the package is not already available locally,npxcan retrieve executable package content from the configured package registry.Because the retrieved package version is mutable and its source is not included in this project, the effective installation code cannot be verified as part of this audit. A compromised package release, registry account, dependency, or registry configuration could consequently cause arbitrary code to run during installation.
The project contains no evidence that the package is currently malicious. The vulnerability is the unpinned trust relationship and execution of externally supplied package code.
Attack Path
- An attacker compromises the
clawhubpackage, one of its dependencies, its publishing account, or the package source selected by the user's registry configuration. - The attacker publishes a malicious version containing an installation hook or malicious runtime behavior.
- A user follows the declared installation instruction:
shell npx clawhub install mentorship npxretrieves the attacker-controlled or compromised package version.- The malicious package executes with the privileges of the user running the installation command.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that account's privileges and environment, the malicious package could read or modify user-accessible files, steal credentials or tokens, alter installed skills, ex ...[truncated 310 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific reviewed version rather than allowingnpxto resolve a mutable current version. - Use a trusted and explicitly configured package registry.
- Record and verify package integrity hashes where the installation system supports them.
- Review and lock the package's transitive dependency graph.
- Avoid running the installation command with administrator or root privileges.
- In CI/CD environments, execute installation in an isolated container with restricted filesystem access, network access, and credentials.
- Establish a controlled upgrade process in which new versions are reviewed before updating the pinned version.
- Pin
