T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Package Execution in Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 16
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumComplete Code Snippet:
yaml openclaw: requires: tools: [filesystem] install: "npx clawhub install wage-theft-defense"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity digest. Depending on the local npm environment,npxcan retrieve and execute the currently published version of the package from a configured package registry.Because the package reference is mutable, the code executed during installation may differ from the code that was available when this skill was audited. This creates a supply-chain trust boundary in which compromise of the package, its publisher account, or the configured registry could result in attacker-controlled code being executed.
The audit found no evidence that the current
clawhubpackage is malicious. The vulnerability is the installation process's inability to guarantee that users execute a specifically reviewed package artifact.Attack Path
- An attacker compromises the
clawhubpackage, its publisher account, or a package source trusted by the user's npm configuration. - The attacker publishes a modified package version containing a malicious CLI entry point or installation lifecycle script.
- A user follows the documented command:
npx clawhub install wage-theft-defense. npxresolves and downloads the mutable package version rather than a known, reviewed version.- The malicious package code executes with the permissions of the user running the command.
- The code can access resources available to that user, subject to operating-system and runtime restrictions.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope m ...[truncated 453 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than relying on the latest registry version:yaml install: "npx clawhub@<reviewed-exact-version> install wage-theft-defense" - Publish and verify a cryptographic integrity digest for the package artifact before execution.
- Use an npm lockfile or equivalent immutable dependency manifest where the installation workflow supports it.
- Require installation from an official, authenticated registry and document the expected package publisher and provenance.
- Disable or avoid dependency lifecycle scripts where they are unnecessary.
- Prefer a preinstalled, independently verified CLI over downloading and executing a package at installation time.
- Run installation with least privilege in a restricted environment, without sensitive environment variables or administrative permissions.
- Pin
