T08 · Insecure Dependencies
- Location
SKILL.md:40- Finding
Unpinned ClawHub CLI Enables Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:40-49
Vulnerability Type: Unpinned third-party package execution throughnpx
Risk Level: HighComplete Code Snippet:
markdown ## Lifecycle Actions | Action | Command | |--------|---------| | Install | `npx clawhub install <slug>` | | Update | `npx clawhub update <slug>` | | Info | `npx clawhub info <slug>` | | Remove | `npx clawhub uninstall <slug>` |Technical Analysis
The documented lifecycle commands invoke
npx clawhubwithout pinning the ClawHub CLI to an audited version or verifying package integrity. If the package is not already available locally,npxcan retrieve it from the configured package registry and execute its package lifecycle or CLI code using the current user's privileges.Because the package reference is mutable, the code executed at runtime may differ from the code that was previously reviewed. The documentation warns that ClawHub downloads and executes code, but it does not require a fixed package version, integrity hash, trusted publisher verification, lockfile, or prevention of implicit package installation. Explicit user consent for a lifecycle operation does not verify the authenticity or integrity of the package being executed.
The same unsafe invocation pattern is also documented in
lifecycle.mdfor installation (lifecycle.md:6-10), update checks (lifecycle.md:17-21), updates (lifecycle.md:29-33), and removal (lifecycle.md:38-42).Attack Path
- An attacker compromises the
clawhubregistry package, its publisher account, or the package distribution infrastructure. - Alternatively, an unsafe registry configuration resolves
clawhubto an attacker-controlled package. - The user approves a legitimate-looking skill installation, update, information lookup, or removal operation.
- The Agent executes
npx clawhub ...without a pinned CLI version or integrity con ...[truncated 1058 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the ClawHub CLI to a specifically reviewed version, for example
npx --no-install clawhubafter a controlled installation or an exact-version invocation such asnpx clawhub@<reviewed-version>, subject to the CLI's supported deployment model. - Install dependencies through a lockfile-backed workflow and enforce integrity hashes with a trusted package manager.
- Prevent implicit network installation during routine operations. Provision the verified CLI separately, then require commands to fail if that local version is unavailable.
- Verify package publisher identity, registry provenance, signatures or attestations, and checksums before approving a new CLI release.
- Review both the management CLI and the target skill package before installation or update. Treat each as a separate supply-chain trust boundary.
- Execute package-management operations in a sandbox or least-privileged environment with restricted filesystem, credential, and network access.
- Document an approved-version upgrade process that includes source review, integrity verification, testing, and explicit authorization before changing the pinned version.
- Pin the ClawHub CLI to a specifically reviewed version, for example
