T08 · Insecure Dependencies
- Location
README.md:15- Finding
Unpinned Third-Party Installer Creates a Mutable Supply-Chain Execution Path
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 15–20
Vulnerability Type: Unpinned third-party installation dependency
Risk Level: MediumComplete Vulnerable Code Snippet:
markdown ## Installation Install this skill with one command: ```bash npx skills add ljsd666/openclaw-tradingview-quanttext The same command is repeated in `README.md`, lines 36–39: ```markdown ### 1. Install the Skill ```bash npx skills add ljsd666/openclaw-tradingview-quanttext ### Technical Analysis The installation command invokes the third-party `skills` npm package through `npx` without specifying an exact package version or integrity value. It also identifies the Skill by a mutable repository name rather than an immutable commit or signed release artifact. Consequently, the content executed or installed when a user follows the documentation may differ from the artifact reviewed during this audit. A compromise, ownership transfer, malicious release, or unauthorized modification affecting either the npm installer package or the referenced source repository could introduce attacker-controlled behavior after review. No evidence shows that the currently audited Markdown artifact itself contains malicious executable code. The risk arises from the mutable installation path documented for users. ### Attack Path 1. An attacker compromises, takes control of, or publishes a malicious update to the npm package resolved as `skills`. 2. Alternatively, the attacker compromises or modifies the repository referenced as `ljsd666/openclaw-tradingview-quant`. 3. A user runs the documented unpinned command: ```bash npx skills add ljsd666/openclaw-tradingview-quantnpxresolves the package available at execution time rather than a previously audited and integrity-verified version.- The compromised installer can run attacker-controlled package lifecycle or installer logic, or it can install modified Skill content.
- The resulting actio ...[truncated 921 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the npm installer to an audited exact version:
bash npx --yes skills@X.Y.Z add ...Do not use a floating version range or an unqualified package name.
-
Pin the Skill source to an immutable commit hash or signed release instead of a mutable repository head.
-
Publish cryptographic checksums for release artifacts and instruct users to verify them before installation.
-
Use package-lock or equivalent integrity metadata where the installation mechanism supports it.
-
Document the npm package publisher, source repository, expected package integrity, and verification procedure.
-
Prefer a workflow that downloads a fixed artifact, verifies its signature or checksum, and allows inspection before any installer code runs.
-
Avoid recommending elevated execution. Explicitly state that the installer must not be run with
sudoor an administrator account. -
Correct the contradictory claim in
README.md:11that there are “no external dependencies,” because the documented installation usesnpx, and optional live-data functionality relies on RapidAPI as described inSECURITY.md.
-
