T08 · Insecure Dependencies
- Location
SKILL.md:34- Finding
Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:34-37;scripts/start-gateway.mjs:1-5
Vulnerability Type: Unpinned external dependency execution throughnpx
Risk Level: MediumThe documented startup procedure and bundled wrapper direct users to execute the mutable registry version of
@claws-shield/cli.Relevant code from
SKILL.md:34-37:bash npx @claws-shield/cli gateway --port 8787Relevant code from
scripts/start-gateway.mjs:1-5:js #!/usr/bin/env node // Thin wrapper for starting the gateway from the OpenClaw skill console.log("Starting Claws-Shield Agent Gateway...") console.log("Gateway server not yet available in skill mode.") console.log("Use the CLI instead: npx @claws-shield/cli gateway --port 8787")Technical Analysis
The
npxcommand resolves and executes an npm package without specifying an exact version. The project contains no lockfile, integrity metadata, vendored implementation, or other mechanism that binds the command to the version that was reviewed.The local script does not implement or start the advertised gateway. Instead, it instructs the user to run the same external package. Consequently, the effective gateway implementation is mutable code outside this audit scope. A compromised package release, registry account, or unexpected future version could cause arbitrary package code to run under the invoking user's account.
This is a supply-chain weakness rather than evidence that the currently published package is malicious.
Attack Path
- An attacker compromises the npm package, its publisher account, or another part of its release pipeline.
- The attacker publishes a malicious version under
@claws-shield/cli. - A user follows the documented command or the instruction emitted by the bundled wrapper.
npxresolves and downloads the mutable package version from the configured npm registry.- The downloaded package exe ...[truncated 902 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an explicitly reviewed version, for example:
bash npx --yes @claws-shield/cli@1.2.3 gateway --port 8787 - Prefer declaring the package as a project dependency and committing a lockfile containing registry integrity hashes.
- Install dependencies using a lockfile-enforcing workflow such as
npm ci. - Audit the pinned package, its transitive dependencies, executable entry point, and lifecycle scripts before distribution.
- Consider bundling the gateway implementation within the reviewed project so that actual runtime behavior is included in the audit scope.
- Document the expected registry and package publisher, and verify package provenance or signatures where supported.
- Run the gateway under a dedicated least-privileged account with access only to the provider credentials and files it requires.
- Update both
SKILL.mdandscripts/start-gateway.mjsso they reference the same pinned and verified artifact.
- Pin the CLI to an explicitly reviewed version, for example:
