T08 · Insecure Dependencies
- Location
SKILL.md:70- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
``` Examples: ```bash npx clawhub@latest install glmocr npx clawhub@latest install glmv-caption npx clawhub@latest install glm-image-gen ``` The document also recommends bulk installation: ```bash npx clawhub@latest install glmocr glmocr-table glmocr-formula glmocr-handwriting glmocr-sdk glm-image-gen glmv-caption glmv-prompt-gen glmv-resume-screen glmv-grounding glmv-doc-based-writing glmv-pdf-to-ppt glmv-pdf-to-web glmv-prd-to-app glmv-stock-analyst glmv-web-replication ``` ### Technical Analysis The recommended installation procedure invokes `npx` with the mutable `@latest` package tag. This causes npm to resolve and execute whichever version of `clawhub` is designated as the latest release at invocation time. The document does not specify an audited version, integrity hash, lockfile, provenance requirement, or mandatory review step. Consequently, the effective executable code can change after this skill has been reviewed. A compromise of the package publisher, npm account, registry delivery path, or a future package release could cause users and agents following these instructions to execute attacker-controlled code. The risk is amplified by the bulk-installation command because it introduces numerous additional downstream skills in one operation without requiring individual inspection. Line 144 explicitly instructs an agent to recommend this installation method, making execution of the mutable dependency part of the intended workflow. Although the artifact contains no executable scripts of its own, the statement that it “does not execute scripts” may give users an incomplete understanding of the operational risk: following its primary installation i ...[truncated 1708 chars]- Remediation
View remediation
install ``` 2. Document the expected package version and integrity information. Where supported, verify package provenance, registry signatures, or published checksums before execution. 3. Avoid automatically executing newly downloaded packages. Prefer a workflow that downloads or inspects package metadata and contents before installation. 4. Require each downstream skill to be reviewed individually before installation, particularly before using the bulk-installation command. 5. Run installation in a sandbox, container, or otherwise restricted environment with: - No unnecessary credentials in environment variables. - Minimal filesystem permissions. - Restricted network access. - No administrative or root privileges. 6. Clarify the documentation language to distinguish between the absence of bundled local scripts and the execution of externally downloaded installer code. 7. Establish a trusted-version update process so that upgrades occur only after the new package version and downstream skill changes have been reviewed. ]]>
