T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution Through npx Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
yaml metadata: category: skills tagline: >- Change a tire, jump a battery, handle a breakdown and a fender bender — the 10 car skills every driver needs before they need them. display_name: "Vehicle Survival Kit" submitted_by: HowToUseHumans last_reviewed: "2026-03-19" openclaw: requires: tools: [filesystem] install: "npx clawhub install vehicle-survival-kit"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version, package integrity hash, or trusted registry. If the package is not already available locally,npxcan retrieve the current package release from the configured package registry and execute it.Consequently, the code executed during installation is not necessarily the same code that was available when this skill was audited. A compromised package maintainer account, malicious future release, registry compromise, or dependency substitution could alter the effective installation behavior. Package lifecycle scripts may also execute automatically with the permissions of the user running the installation.
This is a supply-chain weakness rather than evidence that the currently referenced package is malicious.
Attack Path
- An attacker compromises the
clawhubpackage, one of its dependencies, its publisher account, or the package distribution channel. - The attacker publishes a malicious version or modifies a mutable dependency used by the package.
- A user follows the skill installation metadata and runs
npx clawhub install vehicle-survival-kit. npxresolves and downloads the unpinned package version from the configured registry.- Malicious package code or lifecycle scripts execute under the installing user's ...[truncated 662 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version, for example through an exact-version invocation rather than an unqualified package name. - Use a trusted, explicitly configured package registry.
- Verify package integrity with a lockfile, cryptographic digest, or signed provenance before execution.
- Audit both direct and transitive dependencies for the pinned release.
- Disable package lifecycle scripts where they are unnecessary, or document and review every script that will execute.
- Prefer installing the audited package separately and invoking the known local binary instead of allowing
npxto resolve a mutable release at runtime. - Add automated dependency monitoring so version updates require review before becoming available to users.
- Pin
