T08 · Insecure Dependencies
- Location
README.md:43- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md:43
Vulnerability Type: Unsafe dependency retrieval and execution
Risk Level: HighVulnerable Code
bash npx clawhub@latest install openclaw-new-agentTechnical Analysis
The installation instructions execute the mutable
latestversion of a third-party package throughnpx. This can download and immediately execute package code without pinning an audited version or verifying a checksum, signature, lockfile, or package integrity value.Because the
latestdistribution tag can be changed after this Skill has been reviewed, the code executed by users may differ from the code considered during the audit. A compromise of the package publisher account, registry, package repository, or release process could therefore turn this documented installation command into an arbitrary-code execution channel.Attack Path
- An attacker compromises the
clawhubpackage, its publisher account, or its release pipeline. - The attacker publishes a malicious version and assigns it to the
latestdistribution tag. - A user follows the documented installation command.
npxretrieves the attacker-controlled release.- Package lifecycle hooks or CLI initialization code execute with the invoking user's privileges.
- The malicious package can access files, credentials, environment variables, and services available to that user.
Impact Assessment
Successful exploitation can provide arbitrary code execution under the account running the installation command. In the intended OpenClaw environment, this may expose OpenClaw configuration, Feishu application credentials, agent workspaces, conversation data, gateway logs, and other files accessible to the user. If the command is run by a privileged account, the impact expands to all resources available to that account.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed version. - Publish and document a cryptographic integrity hash or signed release.
- Verify package provenance and registry identity before installation.
- Disable or separately review package lifecycle scripts where feasible.
- Run installation using a dedicated, least-privileged account.
- Document a trusted version-upgrade process that requires review before changing the pinned version.
- Consider distributing the Skill as a signed, immutable archive rather than relying on a mutable registry tag.
- Replace
