T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned npm Package Execution in Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:15
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code:
yaml install: "npx clawhub install soil-water-management"Technical Analysis
The installation command invokes the
clawhubnpm package throughnpxwithout specifying an exact package version or integrity constraint. If the package is not already available locally,npxcan retrieve and execute the package currently published under that name.Consequently, the code executed during installation is mutable and may differ from the version that existed when this Skill was reviewed. The repository contains no vendored installer implementation, lockfile, checksum, or provenance information that would allow users to verify the retrieved executable package.
This creates a supply-chain risk if the npm package, a maintainer account, or the associated publishing process is compromised. It may also expose users to unexpected behavior introduced by a future package release.
Attack Path
- An attacker compromises the
clawhubnpm package, its maintainer account, or its release pipeline. - The attacker publishes a malicious or backdoored release under the legitimate package name.
- A user runs the documented installation command:
bash npx clawhub install soil-water-management npxresolves and downloads the mutable package release.- The downloaded package executes with the privileges and environment of the user running the command.
- Malicious package code may access files, environment variables, network resources, or other resources available to that user.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the installing user. The accessible scope may include that user's files, development credentials, environment variables, network access, and writable appli ...[truncated 283 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact version that has been reviewed:yaml install: "npx --yes clawhub@<audited-exact-version> install soil-water-management" - Do not use version ranges or floating tags such as
latest, because they preserve the mutable-code risk. - Record and verify package provenance and integrity through the package manager and trusted registry metadata.
- Use a lockfile or an equivalent reproducible installation mechanism where the surrounding installation platform supports one.
- Consider installing the audited CLI dependency separately and invoking the trusted local binary rather than allowing
npxto download executable code implicitly. - Review whether the named Skill installation is also resolved to a mutable release. If supported by ClawHub, pin the Skill itself to an audited version or digest.
- Run installation with a non-privileged account and restrict access to sensitive credentials and environment variables during the installation process.
- Pin
