T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned Globally Installed npm Dependency Cannot Be Independently Verified
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 9 and 22
Vulnerability Type: Unpinned third-party package installed globally
Risk Level: MediumVulnerable Code Snippet
yaml metadata: {"openclaw":{"requires":{"bins":["xianchou"],"env":["XIANCHOU_ACCESS_KEY","XIANCHOU_PROJECT_ID","XIANCHOU_API_URL","XIANCHOU_CONFIG_DIR"]},"primaryEnv":"XIANCHOU_ACCESS_KEY","credentials":{"storage":"~/.xianchou/config.json","configDirEnv":"XIANCHOU_CONFIG_DIR","description":"xianchou auth login 写入的访问凭据,JSON 格式,存储 accessKey、projectId 和 apiUrl。"},"install":[{"id":"npm","kind":"node","package":"@xianchou/cli","bins":["xianchou"],"label":"Install Xianchou CLI (npm)"}],"category":"AIGC","tags":["xianchou","markdown","image-generation","video-generation","cli","ai-tools"]}}bash npm install -g @xianchou/cliThe same unpinned installation command also appears in
README.md:35andreferences/cli-command-guide.md:7.Technical Analysis
The Skill requires installing the mutable npm package
@xianchou/cliglobally without specifying an exact version, package integrity hash, lockfile, or other immutable artifact identifier. The repository contains documentation only and does not include the CLI implementation, so the executable behavior cannot be independently audited from the reviewed project.This is security-sensitive because the installed CLI is expected to:
- Receive and store an access key and project identifier.
- Read local Markdown, image, video, and audio files.
- Upload selected local files to a remote service.
- Make authenticated network requests.
- Download generated assets.
- Modify Markdown or MDX files when
--writeis used.
Global npm installation may also execute package lifecycle scripts with the privileges of the user performing the installation. Because no version is pinned, a future or compromised package release could differ materially from the package behavior intended when the Skill was reviewed.
This findin ...[truncated 1871 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@xianchou/clito an exact, reviewed version in both Skill metadata and every installation example, rather than resolving the latest release. - Provide a trusted package integrity hash or an equivalent immutable artifact attestation and verify it before installation.
- Publish the corresponding CLI source code and build instructions alongside the Skill so reviewers can inspect the executable implementation.
- Use lockfiles and reproducible builds for the CLI and all transitive dependencies.
- Prefer a project-local, sandboxed installation over global installation. Run the CLI with the minimum filesystem and network permissions required.
- Disable npm lifecycle scripts during installation where compatible, for example through an approved installation process using
--ignore-scripts. - Sign releases and publish provenance or software-bill-of-materials information so consumers can verify package origin and dependency contents.
- Document the exact files, environment variables, and network destinations the CLI accesses.
- Store access keys with restrictive filesystem permissions and avoid exposing them to unrelated subprocesses.
- Keep installation instructions synchronized across
SKILL.md,README.md, andreferences/cli-command-guide.mdso users are not directed back to an unpinned command.
- Pin
