T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
- Fix your sleep in two weeks using evidence-based protocols — wind-down rituals, sleep anchoring, caffeine timing, and environment optimization display_name: "Sleep Hygiene Overhaul" openclaw: requires: tools: [calendar, filesystem] install: "npx clawhub install sleep-hygiene-overhaul" ``` ### Technical Analysis The installation command executes `clawhub` through `npx` without specifying a package version or integrity hash. When the package is not already available locally, `npx` can retrieve executable package content from the configured npm registry. Because the effective package version is resolved at installation time, the code executed by this command can differ from the version that was available when the Skill was audited. This creates a supply-chain trust dependency on the npm package, registry configuration, package maintainers, and any package lifecycle behavior. The finding does not establish that the current `clawhub` package is malicious. The vulnerability is the absence of controls that make installation reproducible and constrain which package artifact may execute. ### Attack Path 1. An attacker compromises the publishing account or supply chain for the unpinned `clawhub` package, takes over an abandoned package, or causes package resolution to use an untrusted registry. 2. The attacker publishes a malicious version that contains harmful CLI or package lifecycle behavior. 3. A user invokes the documented installation procedure. 4. `npx` resolves and downloads the attacker-controlled package version. 5. The malicious package code executes under the account and environment used to run the installer. ### Impact Assessment Successfully exploited package code would run with the privileges of the user invokin ...[truncated 502 chars]- Remediation
View remediation
` package reference. 2. Use a lockfile or an internally approved immutable package artifact so installation resolves reproducibly. 3. Verify the package integrity hash or signature before executing downloaded content. 4. Configure the command to use an explicitly trusted registry rather than inheriting an arbitrary user or CI registry configuration. 5. Review package lifecycle scripts and disable them where they are unnecessary. 6. Run installation with the least-privileged account available and avoid exposing unrelated environment secrets. 7. In CI environments, isolate installation in a restricted container with limited filesystem and network access. ]]>
