T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 13
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code Snippet:
yaml install: "npx clawhub install woodworking-maker-basics"Technical Analysis
The installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity hash. If the package is not already available from a trusted local installation,npxcan retrieve and execute a package from the configured registry.Consequently, the code executed during installation can differ from the code reviewed during this audit. Compromise of the package publisher, registry account, package distribution infrastructure, or a future package release could introduce arbitrary installation-time code. The project does not document package provenance, a trusted version, integrity verification, or a requirement to use a previously verified local CLI.
Attack Path
- An attacker compromises the package publisher or distribution channel used to resolve
clawhub, or causes an unsafe package version to be published. - A user follows the declared installation instruction.
npxresolves and downloads the unpinned package from the configured registry.- The retrieved package or its lifecycle scripts execute with the privileges of the user running the command.
- Malicious code can access resources available to that user and may install additional payloads.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include the user's files, environment variables, credentials available to the process, network access, and writable project or configuration directories. If the command is run from an elevated shell, the impact could extend to system-level modification.
- An attacker compromises the package publisher or distribution channel used to resolve
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than allowingnpxto resolve the current registry version. - Verify the downloaded artifact with a lockfile, registry integrity metadata, checksum, or cryptographic signature.
- Document the expected package registry and verified publisher identity.
- Prefer invoking a locally installed and administratively verified CLI.
- Disable or carefully review dependency lifecycle scripts where the package manager supports doing so.
- Run installation with an unprivileged account in a restricted environment and review package changes before deployment.
- Pin
