T08 · Insecure Dependencies
- Location
SKILL.md:60- Finding
Unpinned Third-Party CLI Retrieval and Execution Through npx
- Content
View full analysis
# latest published version ``` `SKILL.md:126-128`: ```bash npx clawic update # update one skill npx clawic update --all # update every installed skill with a newer version ``` `batch.md:7-8`: ```bash npx clawic list # installed + versions; compare against published ``` `local-changes.md:9-12`: ```bash # Fetch the ORIGINAL of the installed version for comparison npx clawic install --dir /tmp/original- diff -r .claude/skills/ /tmp/original- ``` `multi-agent.md:14-15`: ```bash npx clawic list # shows installed skills with their locations and versions ``` `preview.md:6-10`: ```bash # Download without installing into any agent's skills folder npx clawic install --dir /tmp/preview- ``` ### Technical Analysis The Skill instructs the Agent to invoke `npx clawic` without pinning an exact package version or validating package provenance and integrity. When a suitable local package is unavailable, `npx` can retrieve the package resolved under the `clawic` name from the configured package registry and execute its CLI code. Consequently, the code executed during an update operation is not fully represented by the reviewed Skill files and can change after this audit. The instructions provide no lockfile, integrity hash, trusted registry constraint, package signature check, or reviewed version restriction. This is particularly security-sensitive because the invoked CLI is used to inspect, download, and replace Agent skills across project and global installation locations. The issue is a supply-chain trust w ...[truncated 1937 chars]- Remediation
View remediation
list npx --yes clawic@ show npx --yes clawic@ install --dir /tmp/preview- npx --yes clawic@ update ``` 2. Prefer a project-local dependency governed by a committed lockfile. Invoke the locked binary rather than permitting dynamic package resolution. 3. Verify the package source, publisher identity, and integrity metadata before execution. Restrict package resolution to an explicitly trusted registry. 4. Where supported, install the reviewed CLI once and use offline or no-install execution modes for subsequent calls, preventing an audit-time command from silently downloading a newer release. 5. Update the pinned version only through a controlled dependency-review process that examines package changes, lifecycle scripts, transitive dependency changes, and integrity hashes. 6. When fetching an historical Skill for local-change comparison, explicitly request the installed historical version. Do not assume an unversioned install command returns the correct reference copy. 7. Execute update tooling with the minimum necessary filesystem and network permissions. If practical, isolate preview downloads and diffs in a sandbox before allowing the tool to modify Agent installation directories. ]]>
