T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned npx Package Execution Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–17
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable code:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install public-speaking-embodied"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact, reviewed version or package integrity value. If the package is not already available locally,npxcan retrieve it from the configured package registry and execute its command-line entry point.Consequently, the code executed during installation may differ from the code that existed when this skill was reviewed. The effective behavior depends on the package version resolved at installation time, its transitive dependencies, registry configuration, and any package lifecycle behavior. The external
clawhubpackage was not included in the audited project, so its implementation and integrity could not be verified as part of this audit.This is a supply-chain weakness rather than evidence that the current skill contains an intentionally malicious payload.
Attack Path
- An attacker compromises the publishing account, package registry, package release process, or a transitive dependency associated with
clawhub. - The attacker publishes a malicious version that is eligible for resolution by the unpinned
npx clawhubinvocation. - A user or installation system executes the command specified in
SKILL.md. npxdownloads or resolves the attacker-controlled package version.- The malicious package code executes with the operating-system privileges and environmental access of the user running the installation.
- Depending on those privileges, the package could access local files, environment variables, credentials available to the process, or modify user-accessible system state.
Impact Assessment
Successfu ...[truncated 689 chars]
- An attacker compromises the publishing account, package registry, package release process, or a transitive dependency associated with
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact version that has been reviewed, rather than relying on the registry's current version resolution. - Use a lockfile or equivalent immutable dependency manifest to pin transitive dependencies.
- Verify package integrity through registry integrity hashes, signed provenance, or an approved internal artifact repository.
- Disable or tightly control package lifecycle scripts where the installation workflow permits it.
- Run installation with a dedicated, least-privileged account in a sandbox or disposable environment.
- Prevent the installation process from accessing unrelated credentials and sensitive environment variables.
- Continuously scan and periodically re-review the pinned package and its transitive dependency graph before approving upgrades.
- Document the trusted package source and reject packages resolved from unexpected registries.
- Pin
