T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned and Unverifiable Global npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:37-45,SKILL.md:63-66, andREADME.md:34-40
Vulnerability Type: Supply-chain exposure through an unpinned globally installed dependency
Risk Level: MediumVulnerable Code
SKILL.md:37-45:yaml "requires": { "bins": ["clawdo"] }, "install": [ { "id": "npm", "kind": "npm", "package": "clawdo", "bins": ["clawdo"], "label": "Install clawdo (npm global)", }, ],SKILL.md:63-66:bash clawhub install clawdo # installs skill + docs into your workspace npm install -g clawdo # install the CLI binaryREADME.md:34-40:bash # In OpenClaw clawhub install clawdo # Or npm directly npm install -g clawdoTechnical Analysis
The skill package directs users and installation tooling to obtain the mutable
clawdopackage from npm without pinning an exact version or integrity digest. The supplied project contains only documentation; it does not include the CLI source, a lockfile, a package manifest with integrity metadata, or other material that would allow the installed implementation to be audited against this skill package.Consequently, the code executed after installation is determined by whichever release the npm registry resolves at installation time. A global npm installation can also run package lifecycle scripts under the permissions of the installing account. The documentation's claims regarding input sanitization, parameterized SQL, SQLite persistence, immutable autonomy, and append-only audit logging cannot be verified from the supplied artifact.
This finding establishes supply-chain exposure, not evidence that the current npm package is malicious.
Attack Path
- An attacker compromises the npm publisher account, publishing pipeline, package registry entry, or another component able to release the
clawdopackage. - The attacker publi ...[truncated 1155 chars]
- An attacker compromises the npm publisher account, publishing pipeline, package registry entry, or another component able to release the
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact reviewed version rather than resolving the latest release.
- Verify the package using a trusted integrity digest or equivalent cryptographic provenance mechanism before installation.
- Include the CLI source, package manifest, and lockfile in the reviewed release, or link the skill release cryptographically to the exact audited source revision and npm artifact.
- Publish and verify package provenance, use protected publisher credentials, require multi-factor authentication, and restrict release automation permissions.
- Avoid global installation where practical. Run the CLI in a project-local, isolated, or otherwise least-privileged environment.
- Disable npm lifecycle scripts during installation when they are not required, and separately review any scripts before enabling them.
- Ensure automated ClawHub installation resolves the same pinned and reviewed CLI version as the skill manifest.
- Add continuous dependency and release-artifact scanning so changes to the distributed npm package are detected before publication.
