T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned CLI Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable code:
yaml install: "npx clawhub install neighbor-mutual-aid"Technical Analysis
The installation instruction invokes
clawhubthroughnpxwithout specifying an exact package version, integrity digest, or trusted registry. When the package is not already available locally,npxcan retrieve and execute the package currently resolved by the configured npm registry.This creates a supply-chain risk because the code executed during installation can differ from the code reviewed at audit time. A compromised package release, maintainer account, registry configuration, or dependency could cause attacker-controlled CLI or package lifecycle code to run.
The instruction does not itself prove that the current package is malicious. The vulnerability is the absence of controls that ensure users execute the same audited artifact.
Attack Path
- An attacker compromises the package, one of its dependencies, its publisher account, or the package source selected by the user's npm configuration.
- The attacker publishes a malicious version or replaces a dependency used by the CLI.
- A user follows the documented
npx clawhub install neighbor-mutual-aidcommand. npxresolves and downloads the attacker-controlled version because no exact version or integrity value is required.- Malicious CLI or lifecycle code executes with the privileges of the user running the command.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, the attacker could access user-readable files, modify project files, steal locally available credentials, install additional packages, or alter the installed skill. This instruction does not independently provi ...[truncated 116 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the installer to an exact, audited version rather than relying on the latest registry resolution.
- Use package-lock or equivalent lock metadata and verify package integrity hashes.
- Explicitly configure and document the trusted package registry.
- Disable or carefully review lifecycle scripts where feasible.
- Prefer a separately verified installation process that does not implicitly download and execute mutable remote code.
- Regularly audit the installer and its complete transitive dependency tree.
