T08 · Insecure Dependencies
- Location
SKILL.md:71- Finding
Unpinned Global Installation of Third-Party Packages and Skills
- Content
View full analysis
/dev/null; then echo "Installing ClawHub CLI..." npm install -g clawhub fi # Install dependent skills clawhub install openclaw-diary-core clawhub install openclaw-diary-insights ``` Additional global installation instructions include: ```bash npm install -g @anthropic/google-workspace-mcp npm install -g @notionhq/notion-mcp npm install -g mcp-obsidian npm install -g @anthropic/slack-mcp npm install -g twitter-mcp npm install -g dbx-mcp-server npm install -g mcp-rss-aggregator ``` ### Technical Analysis The onboarding instructions direct the Agent to globally install packages and additional Skills without pinning exact versions, validating package integrity, verifying publisher identity, or presenting the resolved artifacts for user review. Global installation increases the effect of a compromised package because its executables become available throughout the user environment. The behavior of an unpinned package can change after this Skill has been reviewed. A malicious package release, compromised publisher account, dependency-confusion event, or compromised transitive dependency could therefore introduce arbitrary installation or runtime behavior without requiring any change to this repository. The installed MCP packages are particularly sensitive because they are intended to access Gmail, Google Drive, Notion, Slack, Dropbox, Twitter, and local files using user credentials. ### Attack Path 1. An attacker compromises a referenced npm package, ClawHub Skill, publisher account, or transitive dependency. 2. The attacker publishes a malicious version under the sam ...[truncated 1093 chars]- Remediation
View remediation
