T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 7
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code:
bash npx clawhub@latest install upwork-proposal-generatorTechnical Analysis
The installation instructions invoke
clawhub@latestthroughnpx. Thelatesttag is mutable and does not identify a fixed, previously audited package version. No lockfile, integrity hash, signature requirement, or trusted-source verification is provided.When followed, this command downloads and executes third-party package code selected by the package registry at execution time. Consequently, the effective installer may differ from the version reviewed by the skill author. This creates a supply-chain exposure if the package, maintainer account, registry response, or a future release is compromised.
Attack Path
- An attacker compromises the package publisher, publishing process, registry distribution path, or a future release associated with the
latesttag. - The attacker publishes a modified
clawhubpackage containing malicious CLI or lifecycle code. - A user follows the documented installation command.
npxresolvesclawhub@latest, downloads the attacker-controlled release, and executes it.- The malicious package runs with the privileges of the user who launched the command.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions, the malicious dependency could access user-readable files, environment variables, credentials, project data, and network resources, or modify files available to that user. System-wide impact would require elevated privileges or a separate privilege-escalation mechanism; neither is demonstrated in the reviewed project.
- An attacker compromises the package publisher, publishing process, registry distribution path, or a future release associated with the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Document the expected package registry and verified publisher identity.
- Verify package provenance, signatures, or published integrity metadata before execution.
- Review the pinned package's CLI entry point and lifecycle scripts before recommending it.
- Use a lockfile or equivalent reproducible dependency manifest where supported.
- Update pinned versions only through a controlled review process that includes source and dependency auditing.
- Consider downloading and verifying the package artifact before execution rather than combining retrieval and execution in a single
npxcommand.
- Replace
