T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Packages and Skills Create a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:42-44,SKILL.md:130-132,SKILL.md:171-174,SKILL.md:371-375, andREADME.md:23-27
Vulnerability Type: Unpinned and unaudited third-party dependency installation
Risk Level: MediumVulnerable Code
SKILL.md:42-44:bash # Install ClawHub CLI (used to install skills) npm i -g clawhubSKILL.md:130-132:bash clawhub install add-minimax-providerSKILL.md:171-174:bash clawhub install add-siliconflow-provider # DeepSeek/Qwen/Kimi clawhub install add-newcli-provider # Claude/GPT/GeminiSKILL.md:371-375:markdown | Skill | Installation command | Description | |------|----------|------| | SiliconFlow | `clawhub install add-siliconflow-provider` | 98+ models, including free models | | MiniMax | `clawhub install add-minimax-provider` | ¥49/month subscription plan | | NewCLI | `clawhub install add-newcli-provider` | Claude/GPT/Gemini |README.md:23-27:markdown | Skill | Installation command | |------|----------| | SiliconFlow (free starting option) | `clawhub install add-siliconflow-provider` | | MiniMax (subscription-based primary option) | `clawhub install add-minimax-provider` | | NewCLI (Claude/GPT/Gemini) | `clawhub install add-newcli-provider` |Technical Analysis
The guide instructs users to install the mutable latest release of the
clawhubnpm package globally and then install three third-party skills by name. None of the commands specify an exact version, immutable release identifier, integrity hash, signature, or trusted source commit.The installed packages and skills are not included in this repository, so their implementation and installation behavior cannot be audited from the submitted files. Package registries and skill marketplaces resolve mutable names at installation time. Consequently, the software installed by a future user may differ fro ...[truncated 2237 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the ClawHub CLI to an exact reviewed version rather than resolving the latest release:
bash npm install --global clawhub@<reviewed-version> -
Pin each provider skill to an immutable version, release identifier, or source commit if ClawHub supports that capability.
-
Publish expected SHA-256 digests or signed provenance information for every referenced artifact and require users to verify integrity before installation.
-
Link each dependency to its official source repository and identify the exact source revision corresponding to the recommended release.
-
Add an explicit review step instructing users to download and inspect the skill manifest, scripts, lifecycle hooks, requested permissions, and network destinations before activation.
-
Prefer a project-local installation over a global npm installation where practical. Disable npm lifecycle scripts during initial retrieval when compatible:
bash npm install --ignore-scripts clawhub@<reviewed-version>Any required scripts should be inspected before being run separately.
-
Perform installation in a least-privileged, isolated environment without production API keys or sensitive OpenClaw configuration. Do not run the installation as root or through
sudo. -
Use lockfiles, trusted registries, package signatures, software bills of materials, and automated dependency monitoring to detect unexpected publisher or artifact changes.
-
Document a regular review process so pinned versions are upgraded only after the new artifacts and their transitive dependencies have been audited.
-
