T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Global Package Installation Followed by Persistent Hook Enablement
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:29andSKILL.md:479-480
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Medium
Category: T08: Insecure DependenciesVulnerable Code
At
SKILL.md:29:bash npm install -g @clawdactual/chitinAt
SKILL.md:479-480:bash openclaw hooks install @clawdactual/chitin openclaw hooks enable chitinTechnical Analysis
The installation instructions retrieve the current version of
@clawdactual/chitinfrom the npm registry without pinning an exact version or verifying a package integrity digest. The package is installed globally and subsequently installed and enabled as an OpenClaw lifecycle hook.This artifact contains only
SKILL.md; it does not include the npm package or hook implementation. Consequently, the executable behavior delivered by the registry cannot be verified through this audit. The package name is consistent with the declared project metadata, and there is no evidence in the reviewed file that the current package is malicious. The risk arises because the remotely resolved package can change after the Skill has been reviewed.Global installation increases exposure compared with a project-local dependency. Enabling the package as a hook also allows its code to run during later agent lifecycle events. The documented hook handles
agent:bootstrap,command:new, andcommand:reset, giving the installed package recurring access to agent context and persistent user data.Attack Path
- An attacker compromises the npm publisher account, registry distribution channel, or a future package release.
- The attacker publishes a malicious version under the expected package name.
- A user follows the documented unpinned installation command.
- npm resolves and globally installs the attacker-controlled release with the invoking user's privileges.
- The user installs and enables the s ...[truncated 1192 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed exact version, for example:
bash npm install -g @clawdactual/chitin@1.4.5 -
Publish and document the expected npm integrity digest or signed provenance for the approved package artifact.
-
Prefer a project-local installation with a committed lockfile instead of a global installation where operationally possible.
-
Require users to inspect or verify the packaged hook implementation before enabling it.
-
Separate installation from activation so users can review package contents before granting lifecycle execution.
-
Document commands for disabling the hook, uninstalling the package, and rolling back to a known-good version.
-
Use npm trusted publishing, mandatory multi-factor authentication, protected release workflows, and provenance attestations to reduce publisher-compromise risk.
-
Run the agent and hook under a dedicated, least-privileged account that cannot access unrelated credentials or sensitive files.
-
