T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code:
yaml install: "npx clawhub install romantic-relationship-maintenance"Technical Analysis
The installation command invokes the
clawhubpackage throughnpxwithout specifying a reviewed version or integrity hash. Depending on the local npm environment and cache state,npxcan retrieve and execute the package version currently resolved by the configured registry.This creates a supply-chain trust boundary outside the audited project. The behavior of the command can change after this skill has been reviewed if the package, package owner, registry account, dependency tree, or configured registry is compromised. The project does not provide a lockfile, checksum, signature, or version constraint that would bind installation to a known artifact.
Attack Path
- An attacker compromises the
clawhubpackage, one of its executable dependencies, its publisher account, or a registry used by the victim. - The attacker publishes a malicious package version containing harmful CLI or lifecycle behavior.
- A user follows the skill installation metadata and runs the unpinned
npx clawhub install romantic-relationship-maintenancecommand. npxresolves and downloads the attacker-controlled version.- The malicious package executes with the permissions of the user running the installation.
This path depends on a supply-chain or registry compromise; the audited file does not itself contain a malicious payload.
Impact Assessment
Successful exploitation could execute arbitrary code with the installing user's privileges. Depending on that user's permissions, the payload could read or modify accessible files, obtain environment variables and credentials, alter installed skills, make network requests, or compromise the user's development envir ...[truncated 96 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific reviewed version, for example by using an explicit version in thenpxinvocation. - Prefer an installation workflow backed by a lockfile and verified package integrity metadata.
- Configure
npxto reject unexpected package installation where operationally appropriate. - Use only a trusted registry and document the expected registry source.
- Review the resolved package and its transitive dependencies before updating the pinned version.
- Where supported, verify signed package provenance or publish and validate a cryptographic checksum for the expected artifact.
- Pin
