T08 · Insecure Dependencies
- Location
scripts/task_analyzer.py:309- Finding
Unpinned Third-Party Package Execution Recommended Through npx
- Content
View full analysis
` search 3. **GitHub** — `web_search` for "openclaw skill " or "claude skill " 4. **npm** — Search for relevant MCP servers or CLI tools ``` From `scripts/task_analyzer.py:309-313`: ```python report.append(f"\n### Recommended Search Platforms\n") report.append(f"1. **SkillHub**: Use `skillhub_install` tool to search") report.append(f"2. **skills.sh**: `npx skills find `") report.append(f"3. **GitHub**: web_search 'openclaw skill '") report.append(f"4. **npm**: Search for relevant MCP servers\n") ``` ### Technical Analysis The generated recommendation instructs users or agents to invoke `npx skills find ` without pinning an audited package version or verifying package integrity and publisher identity. When the named package is not already installed, `npx` can resolve, download, and execute package code from the npm registry. Consequently, an operation presented as a search may execute third-party code with the permissions of the invoking user. The effective code can also change after this Skill has been reviewed because the command does not identify an immutable version or integrity digest. The bundled Python program does not automatically execute this command, so exploitation requires a user or downstream agent to follow the recommendation. Nevertheless, recommending downloadable code execution is unnecessary for search-only functionality and exceeds the minimum privileges required to locate relevant Skills. ### Attack Path 1. A user submits a complex task for which no ...[truncated 1057 chars]- Remediation
View remediation
