T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned and Unverifiable Third-Party npm Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 19–78
Vulnerability Type: Unpinned third-party dependencies and unverifiable supply-chain code
Risk Level: MediumThe documentation instructs users to install multiple npm packages without fixed versions, integrity hashes, a lockfile, or bundled source code.
Vulnerable Code Snippets
SKILL.md, line 19:bash npm install @clawhub/image-analyzerSKILL.md, line 43:bash npm install @clawhub/hf-image-detectorSKILL.md, lines 76–78:bash npm install @raghulpasupathi/image-detectionTechnical Analysis
These commands resolve and install whatever package version the npm registry identifies as current at installation time. Consequently, the effective code can change after this Skill has been audited. npm installations may also execute package lifecycle scripts, such as
preinstall,install, orpostinstall, with the privileges of the user performing the installation.The project contains no package manifest, lockfile, integrity metadata, vendored implementation, or other mechanism through which the installed code can be verified against the reviewed artifact. Because the referenced implementations are absent, claims such as
localOnly, “Local inference,” and “no API calls” cannot be validated from this project.This finding does not establish that the named packages are malicious. The vulnerability is the unsafe and unverifiable dependency-installation process, which creates a supply-chain attack opportunity if a package, publisher account, registry response, or transitive dependency is compromised.
Attack Path
- An attacker compromises a referenced package, its publisher account, or one of its transitive dependencies, or otherwise causes a malicious release to be resolved.
- The attacker publishes a modified package version containing malicious runtime behavior or an npm lifecycle script.
- A u ...[truncated 1197 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to an exact, reviewed version rather than allowing npm to resolve a changing release.
- Provide a package manifest and commit a lockfile containing resolved versions and registry integrity hashes.
- Audit the complete transitive dependency graph before distribution and repeat the review whenever dependencies change.
- Verify package ownership, provenance, signatures, and registry origin. Consider npm provenance attestations where supported.
- Disable lifecycle scripts during installation with
npm install --ignore-scriptswhen the packages do not require them. If scripts are required, inspect and explicitly document each script before execution. - Include or link to auditable source code corresponding exactly to the pinned releases so that local-only and network-privacy claims can be independently verified.
- Run installation and image processing in a least-privileged, network-restricted sandbox without unnecessary credentials or access to unrelated files.
- Document whether images, metadata, or analysis results can leave the local system, especially for reverse-image-search and cloud-analysis features.
- Use automated dependency scanning and fail builds or releases when integrity checks, provenance verification, or vulnerability policies are not satisfied.
