T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Global npm Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 35
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumTechnical Analysis
The setup instructions recommend globally installing the
openclawnpm package without specifying an exact version or integrity constraint:bash npm install -g openclawBecause no version is pinned, npm resolves the package version associated with the current registry tag, normally
latest, at installation time. The reviewed skill therefore does not identify an immutable dependency artifact.npm installation can execute package lifecycle scripts, such as
preinstall,install, andpostinstall, with the permissions of the user running npm. A compromised package release, compromised maintainer account, registry compromise, or maliciously changed future version could consequently execute code during installation. Global installation also places package files and executable shims into shared user-level or system-level npm locations, increasing the scope of a compromised dependency.The audited file does not itself contain a malicious payload, and there is no evidence in the reviewed project that the current
openclawpackage is malicious. The issue is the unsafe, mutable dependency installation method.Attack Path
- An attacker compromises the npm package, its publisher account, release workflow, or relevant registry distribution channel.
- The attacker publishes a malicious version under the version selected by the package's default registry tag.
- A user follows the skill instructions and runs
npm install -g openclaw. - npm downloads the attacker-controlled package because the command does not constrain the version or artifact integrity.
- Malicious lifecycle scripts may execute during installation with the invoking user's privileges.
- The globally installed
openclawexecutable may subsequently run attacker-con ...[truncated 684 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a reviewed exact version, for example:
bash npm install -g openclaw@<reviewed-exact-version> - Update the pinned version only after reviewing its provenance, release notes, dependency changes, and published package contents.
- Prefer a project-local installation with a committed lockfile over a global installation where the workflow permits it.
- Use npm provenance and signature verification mechanisms where available, and obtain packages only from the expected registry.
- Consider installing with lifecycle scripts disabled when compatible with the package:
bash npm install --ignore-scripts openclaw@<reviewed-exact-version> - Avoid running npm installation commands with
sudoor an administrative account. - In controlled environments, mirror and approve the exact package artifact internally and enforce integrity hashes or lockfile verification.
- Pin the dependency to a reviewed exact version, for example:
