T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Third-Party CLI Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4 and 84
Vulnerability Type: Supply-chain risk from a mutable npm dependency
Risk Level: MediumComplete Code Snippet
yaml metadata: {"openclaw":{"requires":{"bins":["noxinfluencer"]},"install":[{"kind":"node","package":"@noxinfluencer/cli","bins":["noxinfluencer"]}],"homepage":"https://www.noxinfluencer.com/skills"}}markdown 1. No CLI or stale command tree → ask the user to install `@noxinfluencer/cli@latest`; verify with `schema --all`.Technical Analysis
The Skill delegates its operational behavior to the third-party npm package
@noxinfluencer/cli, but neither the installation metadata nor the setup instructions pin it to an exact audited version. The explicit use of the mutable@latesttag means that the package installed in the future may differ from the version assessed during this audit.The Skill grants this CLI access to sensitive workflows, including locally persisted or environment-provided credentials, API-backed data, local file uploads, exports, CRM changes, and email or message delivery. Package installation may also execute npm lifecycle scripts unless the environment disables them.
This finding does not establish that the current package is malicious. It identifies a supply-chain weakness through which a compromised publisher account, registry incident, or malicious future release could alter the effective executable payload without any change to the reviewed Skill files.
Attack Path
- An attacker compromises the npm publisher account or another part of the package publication pipeline.
- The attacker publishes a malicious release of
@noxinfluencer/cliand assigns it thelatestdistribution tag. - A user or Agent follows the instruction at
SKILL.md:84and installs@noxinfluencer/cli@latest. - Malicious lifecycle code may execute during installation, or malicious runtime code executes when the Agent invokes
noxinfluencer. 5 ...[truncated 1154 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@noxinfluencer/clito an exact version that has been reviewed, rather than using an omitted version or@latest. - Commit a lockfile containing npm integrity hashes and require lockfile-enforced installation, such as
npm ci. - Verify package provenance, publisher identity, signatures, and registry source before installation.
- Disable npm lifecycle scripts during installation where compatible with the package, or separately review every required lifecycle script.
- Run the CLI with least privilege in a sandbox or restricted service account with only the necessary filesystem and network access.
- Keep credentials out of broadly inherited environments and use narrowly scoped, revocable credentials.
- Establish a controlled dependency-update process in which new versions are reviewed, tested, and explicitly approved before the pinned version changes.
- Monitor package ownership and release metadata for unexpected publisher, repository, or distribution-tag changes.
- Pin
