T08 · Insecure Dependencies
- Location
SKILL.md:69- Finding
Unverified Third-Party Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:69-74; additional occurrences inSKILL.md:18-23andREADME.md:32-58
Vulnerability Type: Unverified npm and npx supply-chain dependencies
Risk Level: MediumVulnerable Code Snippets
SKILL.md:69-74:markdown ## Setup `clawpatch doctor` verifies the install and the provider. The published CLI requires Node.js 22+. If `clawpatch` is missing, install the current published package (`npm install -g clawpatch@0.7.2`). The provider (codex by default) is the user's to install and authenticate — don't run login flows on their behalf.SKILL.md:18-23:yaml install: - id: npm kind: node package: clawpatch bins: [clawpatch] label: Install Clawpatch (npm)README.md:32-58:markdown ## Prerequisites - **Node.js 22+ + npm** — Clawpatch is an npm package (`npm install -g clawpatch@0.7.2`). - **A coding-agent provider CLI** — one of `codex` (default), `claude` (routes through your local Claude Code CLI), `cursor`, `grok`, `opencode`, `pi`, or `acpx`. The skill checks both with `clawpatch doctor` and walks you through install if either is missing. ## Install Install only this skill from the repo: ```bash npx skills add tmchow/agent-skills --skill clawpatchAdd
--globalto install it at the user level instead of the current project:bash npx skills add tmchow/agent-skills --skill clawpatch --globalUpdate later with
npx skills update clawpatch.text ### Technical Analysis The skill instructs an agent or user to obtain and execute registry-resolved npm packages without requiring artifact integrity verification, package provenance validation, or source inspection. Pinning `clawpatch` to version `0.7.2` limits unintended version drift, but it does not independently establish that the registry artifact is authentic or uncompromised. Its transitive depe ...[truncated 2732 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every executable package used through
npx, including theskillsrunner, to a reviewed version rather than relying on registry resolution of the current release. - Publish and document trusted release checksums or signed provenance attestations, and require verification before installation.
- Use npm lockfiles with integrity metadata for project-local installations and retain them in version control.
- Prefer project-local installation over
npm install -gto limit cross-project exposure and make the resolved dependency graph auditable. - Inspect package manifests and tarball contents before first execution. Verify the expected publisher, repository, signatures, provenance, lifecycle scripts, and included files.
- Disable lifecycle scripts during acquisition with
npm install --ignore-scriptswhere the package supports it, then explicitly run only reviewed setup operations. - Use a trusted registry and enforce registry configuration so similarly named packages cannot be resolved from an unintended source.
- Run installation and review tooling in a sandbox or container with minimal filesystem access, no unnecessary credentials, and restricted network access.
- Avoid automatic updates. Review release notes, source changes, dependency changes, and provenance before accepting a new skill or CLI version.
- Document that users must not run these installation commands with administrator or root privileges.
- Pin every executable package used through
