T08 · Insecure Dependencies
- Location
README.md:31- Finding
Unpinned npm Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 31-35
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
markdown ## Installation ```bash npx clawhub install manual-aitext ### Technical Analysis The documented installation command invokes `clawhub` through `npx` without specifying an audited package version or validating package integrity. If the package is not already available locally, `npx` may resolve, download, and execute the version currently published in the configured npm registry. Consequently, the code executed during installation is not immutably tied to the Skill version reviewed in this audit. A compromised npm publisher account, malicious package update, registry compromise, or dependency substitution could cause the command to execute code that was not present during the audit. ### Attack Path 1. An attacker compromises the npm package, its publisher account, its dependency chain, or the registry used by the victim. 2. The attacker publishes or serves a malicious version under the package name `clawhub`. 3. A user follows the installation instructions and runs `npx clawhub install manual-ai`. 4. `npx` dynamically resolves and downloads the attacker-controlled package version. 5. The downloaded package executes with the privileges and environment access of the invoking user. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that account's permissions and environment, attacker-controlled code could read or modify user-accessible files, access environment variables and credentials, alter installed Skills or development tools, establish network connections, or compromise projects accessible to the user. The command does not itself request elevated privileges, so the direct privilege boundary is normally limited to the invoking user's perm ...[truncated 134 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a specific, reviewed version rather than relying on the registry's current version:bash npx clawhub@<verified-version> install manual-ai - Document the package's official registry, source repository, expected publisher, and verified version so users can confirm provenance.
- Where supported, verify the downloaded package against a published integrity hash or signed release artifact before execution.
- Review the pinned package and its transitive dependencies before recommending it as an installation mechanism.
- Update the pinned version only after reviewing the new release, rather than allowing installation behavior to change automatically.
- Advise users to run the installer as an unprivileged account and in an environment without unnecessary secrets or credentials.
- Pin
