T08 · Insecure Dependencies
- Location
README.md:28- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md:28-32
Vulnerability Type: Supply-chain risk from unpinned package execution
Risk Level: MediumVulnerable Code Snippet:
markdown ### Via ClawHub CLI ```bash npx clawhub install clawhub-skill-ranktext ### Technical Analysis The documented installation command invokes the `clawhub` npm package through `npx` without specifying a reviewed version or integrity value. If the package is not already available locally, `npx` may retrieve and execute the version currently resolved by the npm registry. This makes the executed installer mutable after the Skill itself has been reviewed. The repository does not provide a package version, lockfile, checksum, publisher verification procedure, or other mechanism that binds the installation command to a known artifact. This finding does not establish that the current `clawhub` package is malicious. It identifies a supply-chain boundary where a compromised package, compromised maintainer account, or unexpectedly changed release could result in arbitrary code execution. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the relevant package-distribution channel. 2. The attacker publishes or substitutes a malicious version that is selected by the unpinned package reference. 3. A user follows the installation instructions and runs `npx clawhub install clawhub-skill-rank`. 4. `npx` downloads and executes the attacker-controlled package code. 5. The malicious package runs with the permissions of the user who invoked the installation command. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the invoking user's account. Depending on that account's privileges and environment, the malicious installer could read or modify user-accessible files, steal accessible credentials, alter installed Skills, or execute additional commands. The fi ...[truncated 151 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version rather than resolving the latest available release.
- Use an explicit invocation such as
npx --package=clawhub@<reviewed-version> clawhub install clawhub-skill-rank. - Publish the expected package name, version, publisher identity, and integrity hash in the installation documentation.
- Prefer a previously installed and independently verified CLI where practical.
- Review new package versions before updating the documented pin.
- Consider distributing a lockfile or verified installation wrapper that rejects artifacts with unexpected integrity metadata.
- Advise users not to run the installer with elevated privileges.
