T08 · Insecure Dependencies
- Location
setup-guide.md:3- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
thumbgate init --agent openclaw`. - Document the expected package publisher, official source repository, and trusted npm registry. - Provide a lockfile or another reproducible installation mechanism that verifies dependency versions and integrity hashes. - Review package entry points, lifecycle scripts, and transitive dependencies before recommending execution. - Run installation under a dedicated, least-privileged account and avoid invoking the command with `sudo` or an administrator shell. - Prefer downloading a signed release artifact and verifying its signature or checksum before execution. ]]>
