T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Mediumyaml install: "npx clawhub install start-a-micro-business"Technical Analysis
The installation command invokes the
clawhubnpm package throughnpxwithout specifying an exact version or integrity constraint. Depending on the local npm configuration and cache state,npxcan retrieve and execute the current package release from the configured registry.Because the package reference is mutable, the code executed during installation can differ from the code that existed when this skill was reviewed. If the package, publisher account, or configured registry is compromised, malicious CLI or package lifecycle code could run under the installing user's account.
Attack Path
- An attacker compromises the package publisher, publishes a malicious release, or controls the npm registry configured on the target system.
- The user follows the documented installation flow.
npxresolves the unversionedclawhubpackage to the attacker-controlled release.- The package's CLI implementation or applicable lifecycle code executes locally.
- The malicious code operates with the filesystem access, environment variables, network access, and other privileges available to the invoking user.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user running the installation command. Depending on that user's permissions, the malicious package could access local files, read exposed environment variables or credentials, modify user-owned data, install additional software, or communicate with external systems.
The issue does not independently establish administrative access. Its scope is bounded by the privileges and isolation controls applied to the installation process.
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than relying on the latest available release. - Use the expected form supported by the installer, such as
npx clawhub@<exact-version> install start-a-micro-business. - Record and verify the package source and integrity metadata where the package manager and deployment process support it.
- Use a committed lockfile for any maintained installation wrapper or project-level dependency.
- Disable or restrict unnecessary package lifecycle scripts during automated installation where operationally possible.
- Execute installation in a sandbox or least-privileged environment without sensitive environment variables.
- Periodically review the pinned release before deliberately upgrading it.
- Pin
