T08 · Insecure Dependencies
- Location
README.md:15- Finding
Mutable Third-Party Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 15-19
Vulnerability Type: Insecure dependency and supply-chain exposure
Risk Level: MediumVulnerable Code Snippet
markdown Install via ClawHub: ```text npx clawhub@latest install rootdata-cryptotext ### Technical Analysis The documented installation command directs `npx` to resolve and execute the mutable `latest` version of the third-party `clawhub` package. The package version is not pinned, and the command does not verify a cryptographic integrity hash or package provenance. Consequently, the code executed by users may differ from the version that existed when this Skill was reviewed. This creates a supply-chain trust boundary in which compromise of the package registry, publisher account, package release process, or upstream dependency tree could introduce attacker-controlled code. ### Attack Path 1. An attacker compromises the `clawhub` publisher account, release infrastructure, or a dependency included by a future release. 2. The attacker publishes a malicious release and causes it to resolve under the `latest` distribution tag. 3. A user follows the installation command from `README.md`. 4. `npx` downloads the mutable package release and executes it locally. 5. The malicious package runs with the privileges and environment access of the user performing the installation. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the installing user's account. Depending on that user's privileges and environment, the malicious package could access readable files, environment variables, credentials, source repositories, and network resources, or modify files available to that account. The reviewed project itself contains no executable scripts, privilege-escalation logic, or persistence mechanism. Therefore, elevated privileges or system-wide compromise are not established directly by the repository and would depend on the installation ...[truncated 42 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latestreference with an exact, reviewed package version, for example:bash npx clawhub@<reviewed-version> install rootdata-crypto - Document the expected package publisher, registry, and provenance so users can validate the package source.
- Where supported, require signature or provenance verification and validate the package integrity digest before execution.
- Use a lockfile, trusted installer, or controlled internal package mirror to make dependency resolution reproducible.
- Review the pinned package and its transitive dependencies before recommending the command.
- Avoid running installation commands with administrative privileges and use an isolated, least-privileged environment where practical.
- Replace the mutable
