T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Package Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:31andSKILL.md:36
Vulnerability Type: Supply-chain risk caused by automatic execution of an unpinned npm package
Risk Level: MediumVulnerable Code
bash npx -y tsx ${SKILL_DIR}/scripts/main.ts --context claude-codebash npx -y tsx ${SKILL_DIR}/scripts/main.ts --context openclawTechnical Analysis
Both documented execution commands invoke
npx -y tsxwithout specifying a package version, lockfile, or integrity constraint. Iftsxis not already installed locally,npxcan resolve, download, and execute the package from the configured npm registry. The-yoption automatically accepts installation without user confirmation.As a result, the code executed at runtime is not limited to the reviewed project files and can change after this audit. The effective package can also be influenced by the user's npm registry configuration. A compromised upstream release, package-maintainer account, registry, or package-resolution environment could therefore introduce arbitrary executable code.
Attack Path
- A user or agent follows the commands in
SKILL.md. - The environment does not contain a trusted local
tsxexecutable. npxresolves the unversionedtsxpackage through the configured npm registry.- A compromised or otherwise untrusted package version is downloaded.
- Because
-yis used, installation and execution proceed without an interactive approval step. - The package executes with the invoking user's privileges before or while loading the local statistics script.
- Malicious dependency code can access resources available to that user, including the Claude Code and OpenClaw session data that this skill is intended to process.
Impact Assessment
Successful exploitation would allow arbitrary code execution with the privileges of the user invoking the skill. Within that user's permission boundary, malicious package code could read or modify files, ...[truncated 390 chars]
- A user or agent follows the commands in
- Remediation
View remediation
Remediation Suggestions
- Declare an audited, exact
tsxversion inpackage.json; do not use a floating version range. - Commit the generated lockfile and require installation with a lockfile-enforcing command such as:
bash npm ci- Invoke only the locally installed executable, for example:
bash ./node_modules/.bin/tsx scripts/main.ts --context claude-code ./node_modules/.bin/tsx scripts/main.ts --context openclawAlternatively, use
npm exec --offline -- tsx ...after a controlled installation.- Remove
npx -y tsxfrom the runtime instructions so skill invocation cannot silently download new executable code. - Review the pinned package and its transitive dependencies, verify registry provenance and integrity metadata, and update dependencies through an explicit review process.
- Where practical, execute the collector with restricted filesystem and network permissions to reduce the impact of a compromised dependency.
- Declare an audited, exact
