T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
``` The README provides the corresponding installation instructions: ```bash # Clone this skill git clone https://github.com//enhanced-modes.git skills/enhanced-modes # Or use clawhub (if published) npx clawhub install enhanced-modes ``` ### Technical Analysis The installation instructions invoke `clawhub` through `npx` without specifying an audited version, package integrity hash, lockfile, or trusted registry. Depending on the local environment and npm cache state, `npx` can retrieve and execute a package from the configured package registry. Consequently, the code executed during installation is not necessarily the same code that was reviewed in this project. The effective installer may change when a new package version is published or if the package, maintainer account, registry, or dependency chain is compromised. The alternative repository argument is also presented without source-validation requirements. Although the README's GitHub URL is only a nonfunctional placeholder, users following an adapted version of that instruction could clone an untrusted repository if its identity is not verified. ### Attack Path 1. An attacker publishes a malicious version of the resolved `clawhub` package, compromises its maintainer account, compromises an upstream dependency, or influences the package registry used by the victim. 2. A user follows the documented command `npx clawhub install enhanced-modes`. 3. `npx` resolves and downloads the unpinned package or package dependencies. 4. Package lifecycle or installer code executes with the privileges of the invoking user. 5. The malicious installer can access resources available to that user, ...[truncated 713 chars]- Remediation
View remediation
install enhanced-modes ``` 2. Publish and document the exact official registry, package scope, and repository URL. 3. Supply integrity information or verifiable release signatures for distributed artifacts. 4. Review and lock transitive dependencies through an appropriate lockfile and automated dependency auditing. 5. Instruct users to verify the repository owner, release tag, commit hash, and signature before installation. 6. Avoid suggesting arbitrary repository sources. If local-repository installation is supported, require an explicit trust review before execution. 7. Recommend installation with an unprivileged account and within a sandbox or isolated environment. ]]>
