T08 · Insecure Dependencies
- Location
README.md:13- Finding
Unpinned npm CLI Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 13–16
Vulnerability Type: Unpinned third-party installation dependency
Risk Level: MediumVulnerable Code
markdown ### Method 2: ClawHub installation ```bash npx clawhub install nanchang-jbltext ### Technical Analysis The documented installation command invokes `clawhub` through `npx` without specifying an exact package version or integrity value. If the package is not already available in the local cache, `npx` can retrieve it from the configured npm registry and immediately execute its CLI code. Consequently, the code executed during installation is not fully determined by the reviewed Skill artifact. A future package release, compromised package-maintainer account, registry compromise, or malicious dependency introduced into the CLI could alter installation behavior after this audit. The artifact itself does not contain malicious dependency code, and this finding does not establish that the current `clawhub` package is malicious. The risk arises from executing an unpinned, externally maintained package. ### Attack Path 1. An attacker compromises the npm package, a package-maintainer account, the configured registry, or a transitive dependency used by the `clawhub` CLI. 2. The attacker publishes a malicious release under the package name resolved by `npx`. 3. A user follows the installation command in `README.md`. 4. `npx` downloads the currently resolved package release rather than a specifically reviewed version. 5. The malicious package lifecycle or CLI code executes with the privileges of the user running the command. 6. The code may access or modify any resources available to that user. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope could include user-owned files, environment variables, application configuration, credentials available to that process, and writable proj ...[truncated 550 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin the installer to an exact, reviewed version:
bash npx --yes clawhub@<reviewed-exact-version> install nanchang-jbl -
Document the expected npm registry and verify that users are not resolving the package through an untrusted mirror.
-
Publish and document the expected package integrity hash or signed provenance where supported.
-
Prefer a separately installed, organization-approved ClawHub client whose version is managed and audited before use.
-
Avoid recommending elevated execution and explicitly state that installation must run with ordinary user privileges.
-
Review each new installer version before updating the pinned version in the documentation.
-
