T08 · Insecure Dependencies
- Location
README.md:5- Finding
Execution of an Unpinned, Mutable npm Package Release
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 5–7
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumbash npx clawhub@latest install habit-trackerTechnical Analysis
The documented installation command instructs users to execute the package identified by the mutable npm tag
latest. Unlike an exact, audited version, this tag can be reassigned to a different package release after the Skill has been reviewed.npxmay download and execute package code from the npm registry. Consequently, the effective code executed by this command is neither present in the reviewed project nor cryptographically fixed by the documentation. A compromised package maintainer account, malicious release, registry compromise, or unexpected future release could therefore introduce attacker-controlled CLI or lifecycle code.Attack Path
- An attacker compromises the
clawhubnpm package, its publisher account, or its release process. - The attacker publishes a malicious release and assigns the
latestdistribution tag to it. - A user follows the installation instructions and runs
npx clawhub@latest install habit-tracker. npxretrieves the release currently referenced bylatest.- Attacker-controlled package code executes with the operating-system privileges and environment access of the invoking user.
Impact Assessment
Successful exploitation could allow arbitrary code execution under the invoking user's account. Depending on that account's permissions and environment, the malicious package could read or modify accessible files, obtain environment variables or local credentials, make network requests, alter installed content, or execute additional processes. The command does not itself demonstrate privilege escalation; the maximum directly established privilege is that of the user who runs it.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latesttag with an exact, reviewed package version, such asnpx clawhub@1.2.3 install habit-tracker. - Verify the selected release's publisher, provenance, and integrity before recommending it.
- Where the installation workflow permits, use a lockfile and integrity hashes to make dependency resolution reproducible.
- Prefer trusted package releases with npm provenance attestations and protected, multi-factor-authenticated maintainer accounts.
- Review package lifecycle scripts and disable them during installation when they are unnecessary.
- Update the pinned version only after reviewing and testing the new release, rather than automatically tracking
latest.
- Replace the mutable
