T08 · Insecure Dependencies
- Location
SKILL.md:9- Finding
Unpinned CLI Installation and Unverified Remote Skill Updates
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:3,SKILL.md:9-12,SKILL.md:24-34, andSKILL.md:49-53
Vulnerability Type: Supply-chain exposure through unpinned dependencies and unverified remote content
Risk Level: MediumVulnerable Code Snippets
SKILL.md:3:yaml description: Use the ClawdHub CLI to search, install, update, and publish agent skills from clawdhub.com. Use when you need to fetch new skills on the fly, sync installed skills to latest or a specific version, or publish new/updated skill folders with the npm-installed clawdhub CLI.SKILL.md:9-12:markdown Install ```bash npm i -g clawdhubtext `SKILL.md:24-34`: ```markdown Install ```bash clawdhub install my-skill clawdhub install my-skill --version 1.2.3Update (hash-based match + upgrade)
bash clawdhub update my-skill clawdhub update my-skill --version 1.2.3 clawdhub update --all clawdhub update my-skill --force clawdhub update --all --no-input --forcetext `SKILL.md:49-53`: ```markdown Notes - Default registry: https://clawdhub.com (override with CLAWDHUB_REGISTRY or --registry) - Default workdir: cwd; install dir: ./skills (override with --workdir / --dir) - Update command hashes local files, resolves matching version, and upgrades to latest unless --version is setTechnical Analysis
The documented installation command retrieves the latest available
clawdhubnpm package and installs it globally without pinning an exact version or integrity digest. Consequently, the code installed at execution time can differ from the package version that was previously reviewed.The CLI is then instructed to install or update Agent Skills from a remote registry. Several examples omit a version, while
update --all --no-input --forcepermits unattended replacement of local content. Although the documentation states that local files are hashed to identify their ...[truncated 2372 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an explicitly reviewed version, for example
clawdhub@X.Y.Z, and update it only through a controlled dependency-review process. - Record and verify npm lockfile integrity metadata or an independently trusted checksum before installation.
- Prefer a project-local installation over a global installation to reduce cross-project exposure and avoid unnecessary elevated privileges.
- Pin installed Skills to reviewed versions and verify signed manifests, artifact signatures, or trusted checksums before activation.
- Restrict registries to an allowlist of approved HTTPS endpoints. Reject unexpected
CLAWDHUB_REGISTRYvalues and untrusted--registryarguments. - Validate publisher identity and package provenance, including npm provenance attestations where available.
- Avoid unattended forced updates such as
update --all --no-input --forcein production or trusted agent environments. - Download updates into a staging directory, inspect file changes, scan scripts and instructions, and require explicit approval before replacing active Skills.
- Execute the CLI and downloaded Skills with least privilege in an isolated environment that does not expose unrelated credentials or sensitive files.
- Document rollback procedures and retain the hashes and versions of previously approved artifacts.
- Pin the CLI to an explicitly reviewed version, for example
