T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Package Execution During Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-15
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumyaml openclaw: requires: tools: [filesystem] install: "npx clawhub install negotiation-trade"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying a package version or integrity hash. If the package is not available locally,npxcan retrieve and execute the version currently resolved by the configured package registry.Consequently, the executable installation behavior is not fully represented by the reviewed project contents and may change after the audit. Compromise of the package publisher, registry account, package distribution channel, or a future package release could cause arbitrary code to run during installation.
Attack Path
- An attacker compromises the package publisher, registry account, or package distribution process associated with the resolved
clawhubpackage. - The attacker publishes a malicious or backdoored package version.
- A user executes the documented installation command.
npxresolves and downloads the unpinned package version.- Package lifecycle behavior or the package executable runs with the installing user's privileges.
- The malicious package can access or modify resources available to that user.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user performing installation. Depending on the local environment, this could expose user-readable files, authentication material available to the process, project data, and writable system resources. The package could also alter files or install additional components within the user's permission boundary.
- An attacker compromises the package publisher, registry account, or package distribution process associated with the resolved
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specifically reviewed version rather than relying on the latest registry resolution. - Use an explicit trusted registry and enforce lockfile or equivalent package-resolution controls.
- Verify package integrity using a trusted checksum, signature, or registry integrity metadata before execution.
- Review package lifecycle scripts and transitive dependencies for the pinned release.
- Run installation in a restricted environment without unnecessary credentials or access to sensitive files.
- Prefer a distribution mechanism that separates package retrieval from execution and allows the retrieved artifact to be inspected first.
- Pin
