T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:23- Finding
Unpinned Remote Repository and Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23-26
Vulnerability Type: Remote mutable code retrieval and insecure dependency installation
Risk Level: HighComplete Code Snippet
bash git clone https://github.com/TatsuKo-Tsukimi/ClawTrap.git ~/ClawTrap cd ~/ClawTrap && npm installTechnical Analysis
The setup procedure clones the moving default branch of an external Git repository and immediately installs its Node.js dependencies. It does not pin a reviewed commit, verify a cryptographic checksum or signature, or otherwise establish that the downloaded content is the same content that was examined when this skill was published.
Because the game itself is not bundled with the audited skill, its effective code can change independently after review. In addition,
npm installmay execute package lifecycle scripts such aspreinstall,install, andpostinstall. Those scripts execute with the permissions of the user performing the installation. The audited files do not provide sufficient evidence to determine whether the current upstream repository or its dependencies are malicious; the vulnerability is the mutable and unverified execution path.Attack Path
- An attacker compromises the upstream repository, a maintainer account, or a dependency selected during installation.
- The attacker adds malicious application code or a dependency lifecycle script.
- A user follows the skill instructions and clones the current repository state without a commit pin or integrity check.
- The user runs
npm install, which installs the attacker-controlled dependency graph and may execute lifecycle scripts. - The malicious code runs under the installing user's account during installation or when
node server.jsis subsequently launched.
Impact Assessment
Successful exploitation can provide arbitrary code execution with the privileges of the user installing or launching the ...[truncated 403 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the repository to a specific reviewed commit or immutable signed release rather than cloning a moving default branch.
- Publish the expected commit identifier and cryptographic archive checksum in the skill.
- Verify the release signature or checksum before installation or execution.
- Include and review a dependency lockfile, then use
npm ciinstead of unconstrainednpm install. - Pin dependency versions and continuously audit the dependency tree.
- Disable lifecycle scripts with
npm ci --ignore-scriptsunless they are demonstrably required; document and review every required script. - Prefer bundling the reviewed application code with the skill when licensing and distribution constraints permit.
- Run the game in a sandbox or container with restricted filesystem access, a non-privileged account, and narrowly scoped environment variables.
