T08 · Insecure Dependencies
- Location
README.md:31- Finding
Unpinned Package Execution in Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 31–33
Vulnerability Type: Unpinned third-party package execution
Risk Level: Mediumbash npx clawhub install openclaw-agent-optimizeTechnical Analysis
The recommended installation command invokes
clawhubthroughnpxwithout specifying a package version or integrity constraint. If the package is not already available locally,npxcan retrieve the currently published version from the configured package registry and execute its CLI code with the invoking user's privileges.Because the resolved package is mutable and is not tied to a reviewed version, the code executed by this command may differ from the code available when this Skill was audited. Exploitation depends on a supply-chain event such as compromise of the package publisher, registry account, package distribution infrastructure, or local registry configuration.
This issue exists in the documented installation workflow rather than in an automatically executed script shipped by the Skill.
Attack Path
- An attacker compromises the package publisher, registry account, distribution channel, or a registry trusted by the user.
- The attacker publishes or serves a malicious version of the unpinned
clawhubpackage. - A user follows the README and runs
npx clawhub install openclaw-agent-optimize. npxresolves and downloads the attacker-controlled package version.- The malicious package executes with the privileges of the invoking user.
- It may read accessible workspace or user data, modify files, install altered Skill content, access user-level credentials available to the process, or establish additional persistence.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the account running the installation command. The accessible scope could include the OpenClaw workspace, user-owned files, environment variables, package-man ...[truncated 233 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the installer to a specific reviewed version, for example
npx clawhub@<reviewed-version> install openclaw-agent-optimize. - Document the expected package registry, publisher identity, package version, and release provenance.
- Prefer an installation process backed by a lockfile, verified checksum, signed release, or package-manager integrity metadata.
- Advise users to inspect and verify the resolved package before first execution.
- Avoid running the installer with administrator or root privileges.
- Consider making the manual copy-based installation the preferred high-assurance option.
- Establish a process for reviewing and updating the pinned installer version when security fixes are released.
- Pin the installer to a specific reviewed version, for example
