T08 · Insecure Dependencies
- Location
SKILL.md:106- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 106
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable code:
bash npx clawhub install model-router-waaiTechnical Analysis
The documented installation command invokes
clawhubthroughnpxwithout specifying an exact package version or integrity value. If the package is not already available locally,npxcan retrieve it from the configured npm registry and execute it immediately.Consequently, the code executed by this command is not immutable relative to the reviewed project. A future package release, package ownership transfer, registry compromise, or maintainer account compromise could alter installation behavior after this audit. The command also provides no lockfile, checksum, signature verification, or explicit trusted-registry constraint.
No evidence was found that the current project itself contains a malicious payload. The risk arises from the mutable external dependency execution path prescribed by its installation documentation.
Attack Path
- An attacker compromises the publisher account, registry entry, or distribution process for the unpinned
clawhubpackage. - The attacker publishes a modified package version containing malicious lifecycle or CLI code.
- A user follows the installation command in
SKILL.md. npxresolves and downloads the attacker-controlled version because no exact version is pinned.npxexecutes the package with the permissions of the installing user.- The malicious package can access resources available to that user and perform arbitrary actions within that security context.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the affected scope may include user-owned files, accessible credentials, development configuration ...[truncated 192 chars]
- An attacker compromises the publisher account, registry entry, or distribution process for the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed version rather than allowingnpxto resolve the latest available release. - Document and enforce the expected official package registry and package publisher.
- Verify package provenance and integrity through registry signatures, checksums, or an equivalent trusted verification mechanism.
- Use a lockfile where the installation workflow permits it, and review dependency changes before updating the pinned version.
- Prefer installing and auditing the required CLI separately instead of combining remote retrieval and immediate execution.
- Avoid running the installation command with administrative or otherwise elevated privileges.
- Pin
