T08 · Insecure Dependencies
- Location
README.md:5- Finding
Execution of an Unpinned npm Package During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 5–7
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumbash npx clawhub@latest install goal-trackerTechnical Analysis
The documented installation command instructs users to execute the mutable
latestrelease of the third-party npm packageclawhub. Because no exact version or integrity value is specified, the code executed by this command can change after the skill has been reviewed.npxmay download and execute the selected package when it is not already available locally. Consequently, compromise of the package publisher account, npm distribution channel, or a future malicious release could cause users following the documentation to execute attacker-controlled code. The project provides no lockfile, checksum, signature-verification step, or other mechanism that binds this installation command to a reviewed artifact.Attack Path
- An attacker compromises the
clawhubnpm publisher account or otherwise causes a malicious version to become the package'slatestrelease. - A user follows the installation instructions in
README.md. npxresolvesclawhub@latestto the attacker-controlled release and downloads it.npxexecutes the package with the privileges of the current user.- The malicious package can access resources available to that user, subject to operating-system controls.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the installing user's privileges. Depending on that user's permissions and environment, the malicious package could read or modify user-accessible files, access environment variables and locally stored credentials, make network requests, modify development assets, or install additional user-level components.
The issue does not itself demonstrate privilege escalation or prove that the current
clawhubpackage is malici ...[truncated 122 chars]- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
clawhub@latestwith an exact, reviewed version, such asclawhub@X.Y.Z. - Verify the selected package version and document its official registry and publisher identity.
- Where supported, validate the downloaded artifact using a trusted checksum or cryptographic signature.
- Use lockfiles and integrity metadata for package-managed installation workflows.
- Review package lifecycle scripts and transitive dependencies before recommending execution.
- Avoid commands that automatically download and execute mutable remote packages. Prefer a separately verified installation step followed by invocation of the pinned local binary.
- Establish a controlled update process in which new versions are reviewed before the documented pin is changed.
- Replace
