T08 · Insecure Dependencies
- Location
setup.sh:17- Finding
Unpinned Third-Party Package Retrieval and Global Installation
- Content
View full analysis
Vulnerability Details
File Location:
setup.sh:17-19; related installation guidance atSKILL.md:104-109
Vulnerability Type: Unpinned and globally installed third-party dependencies
Risk Level: MediumVulnerable Code
setup.sh:17-19:bash if ! node --input-type=module -e "await import('lineage-code-mini')" 2>/dev/null; then echo "Installing lineage-code-mini..." npm install -g lineage-code-mini fiSKILL.md:104-109:bash npx clawhub@latest install lineage-miniOr manually: copy this
skill/directory into your~/.openclaw/skills/lineage-mini/.Technical Analysis
The setup script installs
lineage-code-miniwithout specifying an exact version or verifying an integrity hash. The documentation similarly recommends executingclawhub@latest. Both package references are mutable: the code retrieved at installation time can differ from the code that existed when this skill was audited.The global npm installation can run package lifecycle scripts with the permissions of the user executing
setup.sh. It also modifies global npm state rather than isolating the dependency within the skill. The project contains no lockfile, package integrity metadata, vendored source, or other mechanism that binds installation to a reviewed artifact.This finding does not establish that either external package is malicious. It identifies a supply-chain boundary that cannot be verified from the supplied project and that allows future package versions or compromised transitive dependencies to introduce executable code.
Attack Path
- An attacker compromises the npm publisher account, package release process, registry delivery path, or a transitive dependency.
- The attacker publishes a malicious release under the expected package name or introduces malicious lifecycle behavior.
- A user runs
setup.sh, or follows the documentednpx clawhub@latestinstallation command.
...[truncated 846 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every package to an exact, reviewed version rather than using an implicit latest version or
@latest. - Install dependencies locally within the project instead of using
npm install -g. - Add a committed lockfile containing npm integrity metadata and use
npm cifor reproducible installation. - Where compatible with package functionality, use
npm ci --ignore-scriptsto prevent automatic lifecycle-script execution. - If lifecycle scripts are required, review and explicitly document them before permitting execution.
- Replace
npx clawhub@latestwith a pinned version and verify the downloaded artifact against a trusted checksum or signature. - Run installation under a dedicated, least-privileged account or within a sandbox.
- Include the reviewed dependency source or software bill of materials so the effective executable dependency tree can be audited.
- Pin every package to an exact, reviewed version rather than using an implicit latest version or
