T08 · Insecure Dependencies
- Location
README.md:37- Finding
Unpinned npm Package Is Downloaded and Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 37-40
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumComplete Code Snippet:
markdown ### Option 3: One-Click Install ```bash npx clawhub install scenario-forecastertext ### Technical Analysis The documented installation command invokes `clawhub` through `npx` without specifying an exact package version, integrity hash, lockfile, or verified registry source. If the package is not already available locally, `npx` can retrieve the currently published version from the configured npm registry and immediately execute its CLI code. This creates a time-of-use supply-chain boundary: the code executed by users can change after this Skill has been reviewed. Compromise of the package publisher account, publication of a malicious release, registry substitution, or manipulation of the user's npm registry configuration could therefore turn the documented installation step into arbitrary local code execution. The audited project itself does not contain malicious scripts, and exploitation depends on compromise or substitution of the external package. Nevertheless, presenting the command as a one-click installation method exposes users to mutable, unreviewed executable content. ### Attack Path 1. An attacker compromises the npm publisher account or distribution path for the `clawhub` package, or causes a victim to use an attacker-controlled npm registry. 2. The attacker publishes or serves a malicious package version containing harmful CLI or lifecycle code. 3. A user follows the installation instructions and runs `npx clawhub install scenario-forecaster`. 4. Because no version or integrity value is pinned, `npx` resolves and downloads the attacker-controlled release. 5. The malicious package executes with the operating-system privileges of the user who invoked the command. 6. The payload can access resources available ...[truncated 737 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto an exact, reviewed package version rather than allowingnpxto resolve the latest release:bash npx --yes clawhub@EXACT_VERIFIED_VERSION install scenario-forecaster - Document the expected npm registry and the verified publisher or package provenance.
- Publish an integrity digest or signed release information that users can validate before execution.
- Prefer installing dependencies through a committed lockfile and reviewing the resolved dependency tree before running the CLI.
- Recommend running the installer with a non-privileged account in an isolated environment without sensitive credentials.
- Establish a release-review process so the pinned version is updated only after its package contents, lifecycle scripts, and transitive dependencies have been inspected.
- Pin
