T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Package Execution Through npx Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12-15
Vulnerability Type:T08: Insecure Dependencies
Risk Level: Mediumyaml openclaw: requires: tools: [filesystem] install: "npx clawhub install teaching-physical-skills"Technical Analysis
The installation metadata invokes
clawhubthroughnpxwithout specifying an exact reviewed version or package integrity value. When the package is not already available locally,npxmay download and execute the currently resolved registry version. Consequently, the code executed during installation can differ from the code that was available when this Skill was audited.Package entry points and lifecycle behavior execute with the privileges of the user running the installation. Compromise of the package, its registry account, or a transitive dependency could therefore introduce arbitrary code into the installation process.
The Skill also declares access to the
filesystemtool, although its documented physical-skill teaching workflows do not identify a feature that requires filesystem access. This unnecessarily increases the potential scope of damage if the installation dependency or runtime behavior is compromised.Attack Path
- An attacker compromises the
clawhubpackage, its maintainer account, its dependency chain, or the package source selected by the user's registry configuration. - The attacker publishes a malicious version that remains compatible with the unversioned package resolution.
- A user follows the installation metadata and runs
npx clawhub install teaching-physical-skills. npxresolves and downloads the attacker-controlled version because no exact version or integrity constraint is specified.- The malicious package executes through its command entry point or installation lifecycle with the invoking user's privileges.
- The payload may read, create, alter, or delete files accessible to that user, ...[truncated 936 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than relying on the latest registry resolution:yaml install: "npx --yes clawhub@X.Y.Z install teaching-physical-skills" - Prefer a lockfile-backed installation process with package integrity hashes. Commit the lockfile and enforce immutable or frozen dependency installation in CI.
- Avoid implicit package downloading during execution. Install the verified CLI through a controlled provisioning step and invoke the trusted local binary afterward.
- Verify package provenance, registry source, signatures or attestations, and published integrity metadata before installation.
- Audit the pinned package and its complete transitive dependency tree, including lifecycle scripts and command entry points.
- Run installation with a non-privileged account in a sandbox or container that has no production credentials and only narrowly scoped filesystem access.
- Remove
tools: [filesystem]unless a documented workflow genuinely requires it. If it is required, restrict access to a dedicated working directory and prohibit access to credentials, home-directory secrets, and unrelated project files. - Add automated dependency monitoring and require explicit review before updating the pinned version.
- Pin
