T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned npm CLI Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: MediumVulnerable Code Snippet:
yaml install: "npx clawhub install shift-work-recovery"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying a reviewed package version or integrity constraint. If the package is not already installed locally,npxmay retrieve the current package release from the configured npm registry and execute it with the installing user's privileges.Because the effective executable can change after this Skill has been reviewed, the repository alone does not establish which implementation will run. The project also contains no lockfile, package manifest, integrity hash, or vendored implementation with which to verify the fetched dependency. This creates a mutable dependency boundary and exposes installation to upstream account compromise, malicious package publication, registry substitution, or an unexpectedly unsafe future release.
No evidence indicates that the current
clawhubpackage is malicious. The vulnerability is the installation mechanism's inability to guarantee that the reviewed dependency is the one ultimately executed.Attack Path
- An attacker compromises the upstream
clawhubpackage, its publisher account, or the package source selected by the user's npm configuration. - The attacker publishes a malicious or compromised version under the package name resolved by
npx. - A user follows the Skill installation metadata and runs
npx clawhub install shift-work-recovery. npxretrieves the mutable package version because no exact version or integrity value is specified.- Package installation hooks or CLI code execute with the privileges of the user performing the installation.
- The malicious dependency can access data and resources available to th ...[truncated 619 chars]
- An attacker compromises the upstream
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, reviewed version, for example through a command equivalent to
npx clawhub@<reviewed-version> .... - Use a lockfile and registry-supported integrity verification where applicable.
- Document the expected official package registry and publisher identity.
- Prefer installing the CLI as a declared, locked dependency and invoking its local binary rather than dynamically retrieving the latest package.
- Review package lifecycle scripts and the complete transitive dependency tree before approving updates.
- Execute installation in an isolated, unprivileged environment without production credentials or unnecessary filesystem access.
- Introduce an update process that reviews and tests each new pinned version before changing the installation metadata.
- Pin the CLI to an exact, reviewed version, for example through a command equivalent to
