T08 · Insecure Dependencies
- Location
README.md:6- Finding
Unpinned Remote Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a simple cycling-tracker skill with disclosed CLI examples and no artifact-backed evidence of hidden, destructive, or credential-seeking behavior.
Before installing, consider pinning the ClawHub installer to a reviewed version instead of using `@latest`, and verify why the package declares a `curl` requirement. The skill itself appears limited to cycling-tracking commands and does not request credentials or persistent system access.
README.md:6Unpinned Remote Package Execution Through npx
The install command uses npx clawhub@latest, which fetches and executes the latest published package version at install time rather than a pinned, reviewed release. This creates a supply-chain risk: if the package or one of its distribution paths is compromised later, users following the README could run attacker-controlled code.
The manifest description and introductory text present the skill in Chinese only, which can amount to a language policy violation when no user opt-in or alternative language option is provided. Nothing in the file indicates that this skill is intended only for a Chinese-speaking or region-specific audience.
The skill description is presented in Chinese at L03, and the rest of the README headings and content continue in Chinese without indicating any language choice or user opt-in. This can violate a language/locale policy when users are not given an explicit option to use another language.
No suspicious patterns detected.