T08 · Insecure Dependencies
- Location
SKILL.md:70- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 70-75
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
markdown ## Installation / 安装 ```bash npx clawhub install data-generator-waaitext ### Technical Analysis The documented installation procedure invokes `clawhub` through `npx` without specifying a reviewed package version or verifying package integrity. If the package is not already installed locally, `npx` can retrieve the currently published package from its configured registry and immediately execute it. Consequently, the code executed by this command can change independently of the audited skill. A compromised maintainer account, registry compromise, dependency-confusion condition, or malicious replacement release could cause users following the documentation to execute attacker-controlled code. This finding concerns the installation instruction itself. The audited Python implementation does not independently retrieve or execute remote source code. ### Attack Path 1. An attacker compromises the package publication account, registry entry, or an upstream component used by the unpinned `clawhub` package. 2. The attacker publishes a malicious release under the package name resolved by `npx`. 3. A user follows the documented installation command. 4. `npx` downloads the currently resolved package release because no trusted version or integrity value is specified. 5. The downloaded CLI or its installation lifecycle code executes with the privileges of the user running the command. 6. The malicious package can access files, environment variables, credentials, and network resources available to that user. ### Impact Assessment Successful exploitation permits arbitrary code execution under the installing user's account. The affected scope can include the user's project files, home-directory data, accessible environment credentials, an ...[truncated 338 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version, for example by using an exact package version rather than resolving the latest release. - Record and verify the package integrity hash through an appropriate lockfile or package-manager integrity mechanism.
- Use an explicitly configured and trusted package registry.
- Review package lifecycle scripts and the dependency tree before approving version updates.
- In CI environments, use a pre-reviewed dependency cache or immutable build image rather than downloading executable packages at runtime.
- Run installation with the least-privileged account possible and avoid exposing unrelated credentials in the installation environment.
- Establish a controlled update process that reviews new package versions before changing the pinned version.
- Pin
