T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned ClawHub Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35, 38, 62, 65, 70, 75, 80, and 85
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
bash # Search skills npx clawhub search "keyword" # Browse categories npx clawhub browsebash # Web search skills npx clawhub search "web search" # Weather skills npx clawhub search "weather" # Document skills npx clawhub search "document"bash # Tavily skills npx clawhub search "tavily" # GitHub skills npx clawhub search "github" # Calendar skills npx clawhub search "calendar"bash # Most installed skills npx clawhub search --sort installs # Most starred skills npx clawhub search --sort starsTechnical Analysis
The skill repeatedly instructs users or agents to invoke the
clawhubpackage throughnpxwithout specifying an exact package version, lockfile, integrity hash, or trusted local installation. When the package is not already installed locally,npxcan resolve and download a mutable package release from the configured package registry before executing it.This creates a third-party supply-chain trust boundary that is not represented in the reviewed artifact. The effective executable code can change after this skill has been audited. A compromised registry account, package takeover, malicious future release, or registry-resolution attack could therefore cause attacker-controlled package or lifecycle code to execute.
The project itself contains no executable scripts, and there is no evidence that the current
clawhubpackage is malicious. The risk arises from the unsafe, unpinned dependency-execution pattern.Attack Path
- An attacker compromises the package publisher, registry account, distribution infrastructure, or a future package release.
- The attacker publishes a malicious version that can be selected by the unversi ...[truncated 1077 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace unversioned commands with an exact, reviewed package version, for example:
bash npx --yes clawhub@<reviewed-exact-version> search "keyword" - Prefer installing the reviewed CLI through a controlled dependency manifest and lockfile rather than allowing an implicit download each time the skill is used.
- Verify the package source and record registry integrity metadata or checksums in the deployment process.
- Configure package installation to use a trusted registry and enforce organizational allowlists where available.
- Disable or suppress unnecessary dependency lifecycle scripts during installation when compatible with the CLI.
- Execute the CLI in a restricted environment with minimal filesystem, credential, and network access.
- Document an approved package version and require security review before updating it.
- Avoid presenting unpinned
npxexecution as the default workflow; if a trusted local binary is required, invoke that binary directly and fail safely when it is unavailable.
- Replace unversioned commands with an exact, reviewed package version, for example:
