T08 · Insecure Dependencies
- Location
README.md:27- Finding
Unpinned Third-Party Installation Commands Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 27-32
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: Mediumbash 3. `requests` library: `pip install requests` ### Install the Skill ```bash npx clawhub install zhihutext ### Technical Analysis The installation instructions resolve third-party packages without specifying reviewed versions, lockfiles, package hashes, or integrity metadata. As a result, the installed code can change independently of the audited Skill. `pip install requests` selects the version currently resolved by the configured Python package index. The `npx clawhub install zhihu` command may download and execute the currently resolved `clawhub` package. In particular, `npx` can execute remotely retrieved package code, including package lifecycle behavior, without the project pinning the package to an audited release. This is a supply-chain weakness rather than evidence that either dependency is currently malicious. Exploitation would require compromise or substitution of a package, registry, release, dependency, or package-resolution source. ### Attack Path 1. An attacker compromises a relevant package or release, publishes a malicious version under a package name that the commands resolve, or influences the user's registry configuration. 2. A user follows the documented `pip install requests` or `npx clawhub install zhihu` instruction. 3. The package manager resolves the attacker-controlled or compromised version because no exact reviewed version or integrity hash is required. 4. Installation hooks, package execution through `npx`, or subsequently imported dependency code runs in the user's environment. 5. Malicious code can act with the permissions of the user running the installation or Skill. ### Impact Assessment Successful exploitation could allow arbitrary code execution with the installing user's privileges. Depending on t ...[truncated 528 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every dependency and installation tool to an exact, reviewed version.
- Provide a dependency lockfile generated from reviewed artifacts.
- Require cryptographic hashes for Python packages, such as through a hash-locked requirements file and
pip install --require-hashes. - Replace implicit
npxresolution with an explicitly pinned package version and use integrity verification where supported. - Document the expected package registries and recommend rejecting untrusted registry overrides.
- Review package provenance, release signatures, transitive dependencies, and lifecycle scripts before updating pinned versions.
- Run installation and the Skill as an unprivileged user in an isolated environment with access only to the required Zhihu credentials and network destination.
