T08 · Insecure Dependencies
- Location
SKILL.md:741- Finding
Unpinned Third-Party CLI Execution and Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 741–757
Vulnerability Type: Supply-chain risk through mutable third-party dependencies
Risk Level: MediumVulnerable Code
markdown ## Optional Enhancement Skill Installation Guide The following Skills are not required, but installing them can significantly improve search and fetching capabilities: ### multi-search-engine ```bash npx clawhub@latest install multi-search-enginexcrawl-search + xcrawl-scrape
bash npx clawhub@latest install xcrawl-search npx clawhub@latest install xcrawl-scrapetext ### Technical Analysis The installation instructions invoke `npx clawhub@latest`, which downloads and executes the version currently published under that package name. Neither the CLI version nor its integrity is pinned. The CLI subsequently installs additional third-party Skills whose versions, contents, publishers, and integrity are also not constrained by the audited project. This creates a mutable remote execution chain: the code executed when a user follows the instructions can differ from the code available when the Skill was reviewed. A registry compromise, malicious package update, dependency confusion event, or compromise of one of the installed Skills could therefore introduce arbitrary code into the Agent environment. These enhancements are optional and relevant to the declared search functionality, but executing mutable third-party packages is not necessary for the core workflow, which already declares `WebSearch` and `WebFetch`. The recommendation consequently exceeds the minimum dependencies needed for basic operation. ### Attack Path 1. An attacker compromises the `clawhub` registry package, its publisher account, its dependency chain, or one of the named third-party Skills. 2. The attacker publishes a malicious release or modifies the payload delivered under the mutable `latest` tag. 3. A user follows the installation guide and runs `npx clawhub@latest ...[truncated 967 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
clawhubto a reviewed exact version instead of using@latest. - Pin every installed Skill to an immutable version, release digest, or commit.
- Verify package publishers, signatures, checksums, and provenance before installation.
- Maintain an allowlist of reviewed Skills and trusted registries.
- Inspect downloaded package contents and dependency lockfiles before activation.
- Run installation and third-party Skills in a sandbox with restricted filesystem, network, process, and secret access.
- Do not expose API keys to optional Skills unless explicitly required; use scoped, revocable credentials.
- Separate installation from normal Skill execution and require informed user approval.
- Document reviewed versions and establish a controlled update process that includes security re-audit.
- Prefer the already declared
WebSearchandWebFetchtools where they satisfy the task, avoiding optional package execution entirely.
- Pin
