T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned npm CLI Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:14
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install tool-fluency"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity value. If the package is not already available in the local npm cache,npxmay retrieve a currently resolved release from the configured npm registry and execute it.Consequently, the code executed during installation can differ from the code that was available when this Skill was reviewed. The project contains no lockfile, vendored CLI implementation, package integrity hash, or other mechanism that constrains the resolved
clawhubpackage to a reviewed artifact.Exploitation requires control over, or compromise of, the package distribution path—for example, compromise of the package publisher, registry account, registry infrastructure, or the user's registry configuration. The command alone does not demonstrate that the current
clawhubpackage is malicious, but its unpinned execution creates an avoidable supply-chain exposure.Attack Path
- An attacker compromises the
clawhubnpm package, its publisher account, or another component of the configured package-resolution path. - The attacker publishes or serves a modified package version containing malicious installation or CLI code.
- A user or automation system processes the Skill's installation metadata and runs
npx clawhub install tool-fluency. npxresolves and downloads the attacker-controlled package because the command does not constrain the version or verify an integrity hash.- The package executes with the privileges and environment of the user running the installation command.
Impact Assessment
Successful exploita ...[truncated 677 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin
clawhubto an exact, reviewed version rather than relying on the registry's current resolution:yaml install: "npx --yes clawhub@<reviewed-exact-version> install tool-fluency" -
Verify the selected package artifact against an approved integrity hash or signed provenance before execution.
-
Use a trusted, explicitly configured registry and enforce dependency allowlisting in automated installation environments.
-
Prefer installing dependencies through a lockfile-controlled workflow and invoke the locked local binary rather than allowing
npxto download a package dynamically. -
Run installation with minimum privileges in a sandbox or isolated container, without unrelated credentials or sensitive environment variables.
-
Periodically review the pinned package version and update it only after inspecting the new artifact and validating its provenance.
-
