T08 · Insecure Dependencies
- Location
README.md:29- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md:29
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
bash npx clawhub@latest install pushplus-notificationTechnical Analysis
The documented installation command instructs users to download and execute the mutable
latestversion of theclawhubpackage. No exact version, lockfile, checksum, signature, or other integrity constraint is specified.Because the version associated with
latestcan change after this Skill has been reviewed, the code ultimately executed by users is outside the reviewed artifact. The command may also invoke package CLI or lifecycle code with the permissions of the user runningnpx.This creates a supply-chain trust boundary in which compromise of the package, its publishing account, the package registry, or a future release could result in execution of code that was not present during this audit.
Attack Path
- An attacker compromises the upstream package, its maintainer account, or the release process.
- The attacker publishes a malicious release and assigns it the
latestdistribution tag. - A user follows the installation instructions and runs
npx clawhub@latest install pushplus-notification. npxdownloads the current mutable package release.- The package's CLI or lifecycle behavior executes locally with the invoking user's privileges.
- The malicious package can access files, environment variables, credentials, and network resources available to that user.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. The accessible scope may include the user's home directory, project files, environment variables, agent credentials, SSH configuration, and any services reachable from the host.
The reviewed project does not itself contain evidence that the cu ...[truncated 117 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Publish and verify the expected package provenance, checksum, or signature.
- Prefer an installation mechanism backed by a lockfile and integrity metadata.
- Review the pinned package's lifecycle scripts and transitive dependencies before recommending execution.
- Document a manual installation path that copies the audited Skill files without executing third-party package code.
- Update pinned versions only after reviewing the new release.
- Replace
