T08 · Insecure Dependencies
- Location
README.md:8- Finding
Execution of an Unpinned npm Package During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 8
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code:
bash npx clawhub@latest install heart-rate-trackerTechnical Analysis
The documented installation procedure uses
npxto download and execute the release currently referenced by the mutablelatesttag. The project does not pin an exact reviewed version or specify an integrity hash or signature.Consequently, the code executed by this command may differ over time from the code that was available when the skill was reviewed. The risk materializes if the npm package, its publisher account, its dependencies, or the mutable release tag is compromised. The audit did not establish that the referenced package is currently malicious.
Attack Path
- An attacker compromises the
clawhubnpm package, its publisher account, a transitive dependency, or the publication workflow. - The attacker publishes a malicious release and assigns or causes the
latesttag to resolve to that release. - A user follows the installation command from
README.md. npxretrieves and executes the attacker-controlled package.- The malicious package runs with the operating-system privileges of the user who invoked the command.
Impact Assessment
Successful exploitation could permit arbitrary code execution within the invoking user's security context. Depending on that user's privileges and accessible resources, this may expose local files, environment variables, authentication tokens, project credentials, and network-accessible services. If the command is run under an administrative account or in a privileged CI environment, the impact may extend to broader system or pipeline compromise.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Verify the package using registry-supported integrity metadata or cryptographic signatures.
- Document the expected files, commands, and permissions involved in installation.
- Use a trusted registry and enable protections such as publisher multifactor authentication and provenance attestations.
- Review and lock transitive dependencies where the installation model permits it.
- Advise users not to run installation commands with administrative privileges.
- Re-audit the package before updating the pinned version.
- Replace
