T08 · Insecure Dependencies
- Location
README.md:65- Finding
Unpinned Packages Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md:65-75
Vulnerability Type: Supply-chain risk from unpinned executable dependencies
Risk Level: MediumVulnerable Code:
markdown ## Install **ClawHub (OpenClaw)**: ```bash npx clawhub@latest install interview-analysisOther (e.g. skills.sh):
bash npx skills add mikonos/interview-analysistext ### Technical Analysis The documented installation commands cause `npx` to retrieve and execute third-party packages from a package registry. The first command explicitly selects `clawhub@latest`, while the second invokes the unversioned `skills` package. Neither command pins an audited version or verifies a cryptographic signature or integrity digest. Consequently, the code executed when a user follows the documentation may differ from the version originally reviewed. A compromised package publisher, registry account, transitive dependency, or subsequently malicious release could introduce arbitrary executable behavior. This issue requires a user or automation system to run one of the documented installation commands; the repository itself does not contain an embedded malicious script. ### Attack Path 1. An attacker compromises the publisher account, package distribution channel, or dependency chain for `clawhub` or `skills`. 2. The attacker publishes a malicious version under the package name used by the documentation. 3. A user follows `README.md` and executes the applicable unpinned `npx` command. 4. `npx` retrieves the current registry package rather than a fixed, previously audited artifact. 5. The package CLI or applicable lifecycle behavior executes with the privileges and environment of the invoking user. 6. The malicious package can access resources available to that user, subject to operating-system and runtime restrictions. ### Impact Assessment Successful exploitation could permit arbitrary code execution with the i ...[truncated 462 chars]- Remediation
View remediation
Remediation Suggestions
- Pin each installer package to a specific reviewed version, for example
npx clawhub@X.Y.Z, rather than using@latestor an unversioned package. - Use the package manager's option to reject implicit installation where available, ensuring unexpected missing packages are not fetched silently.
- Publish and verify cryptographic signatures or integrity digests for installation artifacts.
- Document the expected package publisher, registry, version, and checksum so users can validate provenance before execution.
- Review and pin transitive dependencies through lockfiles in any maintained installer implementation.
- Run installation under a non-privileged account in a restricted environment, without unnecessary credentials or sensitive environment variables.
- Establish a release process that performs dependency scanning and reproducible verification before updating the documented installer version.
- Pin each installer package to a specific reviewed version, for example
