T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution in Installation Command
- Content
View full analysis
- Every cutting tool you own is probably dull. A sharp knife is safer than a dull one. Here's how to fix all of them in 10 minutes. display_name: "Sharpening" submitted_by: HowToUseHumans last_reviewed: "2026-03-19" openclaw: requires: tools: [filesystem] install: "npx clawhub install sharpening" ``` ### Technical Analysis The installation command invokes `clawhub` through `npx` without specifying an exact package version, lockfile, or integrity hash. When the package is not already available from a trusted local installation, `npx` can retrieve and execute the version currently resolved by the configured package registry. Because the resolved package is mutable independently of this reviewed skill, the code executed during installation may differ from the code available when the skill was audited. A compromised package publisher account, registry compromise, malicious replacement release, or unexpected future release could therefore introduce arbitrary installation-time behavior. The requested `filesystem` capability is also broader than the informational sharpening guidance appears to require. Although this does not establish exploitation by itself, unnecessary filesystem access could increase the consequences of a compromised dependency. ### Attack Path 1. An attacker compromises the `clawhub` package, its publisher account, or the package distribution path. 2. The attacker publishes a malicious version that can be selected by the unversioned `npx clawhub` invocation. 3. A user follows the installation metadata and executes: ```shell npx clawhub install sharpening ``` 4. `npx` resolves and downloads the attacker-controlled package version. 5. The malicious package code or its lifecycle behavior execute ...[truncated 763 chars]- Remediation
View remediation
install sharpening" ``` 2. Verify the selected release against an expected package integrity hash or trusted signed provenance before execution. 3. Use a lockfile where the installation workflow supports one, and commit the lockfile with the reviewed artifact. 4. Restrict dependency retrieval to an approved registry using authenticated and integrity-protected configuration. 5. Review package lifecycle scripts and installation behavior before publishing the command. 6. Prefer a preinstalled, organization-managed `clawhub` binary over downloading and executing a package during each installation. 7. Remove the declared `filesystem` requirement if the skill does not genuinely need file access. If storage is required, restrict access to a dedicated application directory and apply least privilege. ]]>
