T08 · Insecure Dependencies
- Location
SKILL.md:67- Finding
Unpinned Package Execution in Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:67
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code Snippet:
bash npx clawhub install a2a-waaiTechnical Analysis
The documented installation command invokes a third-party package through
npxwithout specifying an audited version or integrity value. Consequently, the package resolved when the command is executed may differ from the package that existed when this skill was reviewed.This creates a supply-chain trust risk. If the relevant package, publisher account, package registry, or dependency chain is compromised, an attacker could distribute altered installation behavior under the expected package name. The command would then retrieve and execute that changed package in the user's environment.
Attack Path
- An attacker compromises the package, its publisher account, or an associated supply-chain component.
- The attacker publishes a modified release containing malicious installation behavior.
- A user follows the documented command without a pinned version or integrity check.
npxresolves the current package release from the configured registry.- The altered package executes with the privileges of the user running the installation.
Impact Assessment
Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on those privileges, the attacker may be able to access user files, credentials, agent configuration, and network resources or modify other locally accessible software. The exact impact depends on the behavior of the externally supplied package and the privileges under which installation occurs.
- Remediation
View remediation
Remediation Suggestions
- Pin the package to a specific, audited version rather than resolving the latest available release.
- Document the trusted package registry and avoid implicit resolution from untrusted or user-controlled registries.
- Verify the downloaded artifact using a cryptographic integrity hash or signed provenance information.
- Review the package and its transitive dependencies before recommending installation.
- Use a lockfile or equivalent reproducible dependency mechanism where supported.
- Run installation with the minimum required privileges and avoid privileged or administrative execution.
