T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned npm packages are downloaded and executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:6,SKILL.md:47-52,SKILL.md:125-135,SKILL.md:197;references/AVATAR.md:13-18
Vulnerability Type: Supply-chain exposure through mutable third-party dependencies
Risk Level: MediumVulnerable Code
yaml allowed-tools: "Bash(npx openpersona:*) Bash(npx clawhub@latest:*) Bash(openclaw:*) Bash(gh:*) Read Write WebFetch"bash # Agent / scripted usage (always use --preset or --config): npx openpersona create --preset base --install # Human / terminal usage (interactive wizard): npx openpersona createbash # If you wrote persona.json (custom path): npx openpersona create --config ./persona.json --install # If you chose a preset (preset path): npx openpersona create --preset <name> --installtext To find external skills: check local `layers/skills/`, search ClawHub via `npx clawhub@latest search "<keywords>"`, or fetch `https://skills.sh/api/search?q=<keywords>`.bash npx skills add avatar-runtime # or directly from GitHub: npx skills add github:acnlabs/avatar-runtime/skill/avatar-runtimeTechnical Analysis
The Skill repeatedly directs the agent to use
npxto resolve and execute packages. Theopenpersonaandskillspackage versions are not pinned, whileclawhub@latestexplicitly selects mutable latest content. No lockfile, package integrity hash, signature verification, or approved-version policy is included in the audited project.Because
npxmay download a package before executing its command-line entry point, the effective executable can differ from the artifact that was reviewed. This behavior is relevant to the Skill's management functionality, but allowing unrestricted current releases exceeds the minimum necessary privilege: the same operations could use exact, reviewed versions.This finding establishes supply-chain exposure, not that the current upstream packages are malicious.
Attack Path
- An attacker compromises a ref ...[truncated 1082 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every executable package to an exact reviewed version, for example
npx openpersona@X.Y.Z. - Remove
@latestand establish an explicit, reviewed upgrade process. - Prefer locally installed dependencies governed by a committed lockfile.
- Verify registry provenance, signatures, and integrity hashes before execution.
- Run package CLIs in a sandbox with minimal filesystem, environment, and network access.
- Require explicit user confirmation before first execution and whenever the pinned version changes.
- Maintain an allowlist of approved package names, versions, publishers, and source repositories.
- For GitHub installation sources, pin immutable commit hashes rather than mutable branches or shorthand repository references.
- Pin every executable package to an exact reviewed version, for example
