T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Mutable npm Package Execution in Recommended Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 30
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: MediumVulnerable Code
bash npx clawhub@latest install <skill-slug>Technical Analysis
The recommended installation command uses
npxwith the mutable@latesttag. If the package is not already available locally,npxcan retrieve it and immediately execute its code. Because@latestdoes not identify a fixed, reviewed release or verify an expected integrity value, the code executed by future users may differ from the code available at audit time.The document also states that listed community skills are curated but not audited. Consequently, pinning the installer alone would not establish the trustworthiness of a selected skill; both the installer and the requested skill are relevant supply-chain trust boundaries.
Attack Path
- An attacker compromises the npm publisher account, package, registry delivery path, or a dependency used by a future
clawhubrelease. - A malicious release becomes the version referenced by the mutable
latestdistribution tag. - A user follows the installation command from
SKILL.md. npxdownloads the currently resolved package and runs its executable code.- The malicious package executes with the permissions and environment available to the invoking user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's account. Depending on that account's permissions and environment, the malicious package could read or modify accessible project and user files, access environment variables and locally available credentials, make outbound network requests, or modify user-level configuration.
The finding does not demonstrate an existing malicious
clawhubrelease. It identifies the absence of version and integrity controls in an instruction tha ...[truncated 42 chars]- An attacker compromises the npm publisher account, package, registry delivery path, or a dependency used by a future
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact package version that has been reviewed and approved. - Document the expected npm package integrity hash and verify it through a trusted lockfile or controlled installation process.
- Prefer a previously installed and organization-approved CLI rather than downloading executable code at invocation time.
- Run installation in a restricted environment with minimal filesystem, credential, and network access.
- Require source review and provenance verification for both the installer and each selected community skill.
- Avoid automatically installing skills merely because a repository URL was supplied in chat.
- Establish an update process that separately reviews and approves each new installer version before changing the pinned version.
- Replace
