T08 · Insecure Dependencies
- Location
README.md:21- Finding
Unverified Global CLI Dependency Installation
- Content
View full analysis
/dev/null 2>&1; then echo "codex CLI not found on PATH. Install Codex CLI and authenticate with ChatGPT sign-in." >&2 exit 127 fi cmd=(codex exec --sandbox "$sandbox") ``` Checking only for the executable name does not establish that the binary came from the intended publisher or package. A replaced, compromised, dependency-confused, or otherwise unintended npm package could therefore satisfy the wrapper's check and execute with the user's privileges. ### Attack Path 1. An operator follows the documented `npm i -g codex` installation command. 2. npm retrieves the unscoped and unpinned package available through the configured registry. 3. The package installs an executable named `codex` into the user's global executable path. 4. The wrapper locates that executable using `command -v codex`. 5. A malicious or compromised executable runs when the Skill delegates a task. 6. The executable receives prompts and may access repository data and any resources available to the invoking user. Exploitation depends on the installed package or configured registry being malicious, compromised, or different from the intended Codex CLI. ### Impact Assessment A malicious CLI package would execute with the privileges of the user running OpenClaw. Depending on local perm ...[truncated 418 chars]- Remediation
View remediation
