T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:13
Vulnerability Type: Supply-chain exposure caused by an unpinned executable dependency
Risk Level: MediumVulnerable Code:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install navigation-without-screens"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity value. Depending on the local npm configuration and cache state,npxcan retrieve and execute the package version currently resolved from the configured registry.Consequently, the code executed during installation is not immutable and may differ from the version that was available when this Skill was reviewed. This creates a supply-chain trust boundary in which compromise of the package, publisher account, registry resolution, or a subsequently released version could introduce attacker-controlled installation behavior.
No evidence in the reviewed project shows that the current
clawhubpackage is malicious. The risk arises from the unpinned execution mechanism.Attack Path
- An attacker compromises the package publisher, publishing process, registry account, or another relevant dependency-resolution component.
- The attacker publishes a malicious or backdoored version of the package resolved as
clawhub. - A user runs the documented installation command.
npxretrieves or resolves the compromised package because no reviewed version is pinned.- Package lifecycle or command code executes with the operating-system privileges of the user running the installer.
- The malicious package could access data or modify resources available to that user.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope would depend on that account's privileges, filesystem permissions, avail ...[truncated 401 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than allowing unconstrained package resolution. - Use package-locking and integrity verification mechanisms supported by the installation environment.
- Resolve packages only from an explicitly trusted registry.
- Avoid running installation commands with administrator or root privileges.
- Review package lifecycle scripts and the resolved dependency tree before distribution.
- Where feasible, install from a verified artifact with a cryptographic checksum or signature.
- Establish an update process that requires security review before changing the pinned version.
- Pin
