T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Third-Party Installation Sources Permit Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11–25
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: MediumThe installation documentation instructs users to execute package runners and install content from mutable remote sources:
bash # Install all skills from repo npx skills add https://github.com/barneyjm/camino-skills # Or install specific skills npx skills add https://github.com/barneyjm/camino-skills --skill camino-ev-charger npx clawhub@latest install camino-ev-charger # or: pnpm dlx clawhub@latest install camino-ev-charger # or: bunx clawhub@latest install camino-ev-chargerTechnical Analysis
The GitHub installation commands do not pin the repository to a reviewed commit hash or signed release. Consequently, the content installed by the same command can change after this Skill has been audited.
The package-runner commands explicitly use the mutable
latestdistribution tag. Tools such asnpx,pnpm dlx, andbunxdownload and execute third-party packages in the local environment. If a package publisher account, registry release, repository, or transitive dependency is compromised, these commands may execute attacker-controlled installation logic with the privileges of the user performing the installation.The command that installs all companion skills additionally expands the executable code and dependency surface beyond the specific Skill reviewed in this audit.
No evidence was found that the currently reviewed files are themselves malicious. The vulnerability is the absence of immutable dependency selection and integrity verification in the documented installation process.
Attack Path
- An attacker compromises the relevant package publisher, registry package, GitHub repository, release process, or transitive dependency.
- The attacker publishes malicious content under the mutable
latesttag or changes the repository branch r ...[truncated 1092 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version, such asclawhub@x.y.z. - Pin GitHub installations to a full immutable commit hash rather than a mutable branch or repository default.
- Publish cryptographic checksums or signed release artifacts and verify them before installation.
- Use lockfiles and integrity metadata for package and transitive dependency resolution where supported.
- Recommend installing only the required Skill instead of all companion skills by default.
- Document the expected publisher identity, package source, version, and commit so users can verify provenance.
- Perform installation in a least-privileged or sandboxed environment and explicitly warn users not to run package-runner commands as an administrator.
- Establish dependency monitoring and a release-review process so compromised or unexpected upstream changes can be detected before documentation is updated.
- Replace
