T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Third-Party Executable Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11–15
Vulnerability Type: Unpinned and unauditable third-party executable dependency
Risk Level: MediumVulnerable Code
yaml install: - kind: node package: clawrma bins: [clawrma] homepage: https://github.com/clawrma/clawrmaRelated execution instructions appear at lines 24–26 and 35–41:
markdown - If `clawrma auth status` is not authenticated, run `clawrma auth setup` (clawrma is open source and you should inspect the code before installing) - For OpenClaw: Run this in an interactive terminal and follow the prompts if not already authenticated. - If setup or auth fails, follow the CLI remediation output.markdown - `clawrma fetch <url>`: fetch URL content as JSON - `clawrma search <query>`: run web search as JSON - `clawrma screenshot <url>`: capture a screenshot - `clawrma snapshot <url>`: capture structured page data - `clawrma infer "<prompt>"`: run solver-backed inference - `clawrma status`: show balance, solver state, and capabilities - `clawrma balance`: show account balanceTechnical Analysis
The installation metadata identifies the npm package
clawrmawithout specifying an exact version or package integrity hash. The audited project contains onlySKILL.md; it does not include the dependency source, a lockfile, checksums, or other artifacts that would allow the installed implementation to be verified against a reviewed version.Consequently, package resolution can select a release published or modified after the Skill was reviewed. The external package's lifecycle behavior, authentication implementation, credential storage, network destinations, and command implementations cannot be determined from the audited project. The document recommends inspecting the package before installation, but this is advisory and does not technically enforce review or integrity verification.
This finding establishes a supply-chain exposure, not evidence ...[truncated 1267 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
clawrmato an exact, security-reviewed package version rather than using a mutable package reference. - Commit a lockfile and verify the registry-provided integrity hash during installation.
- Review and record the source corresponding to the pinned release, including package lifecycle scripts and transitive dependencies.
- Disable npm lifecycle scripts during installation where compatible with the package's documented requirements.
- Vendor the reviewed implementation or use a controlled internal package registry if stronger supply-chain assurance is required.
- Document the CLI's expected network destinations, authentication flow, credential-storage mechanism, and data-retention behavior.
- Require explicit user confirmation before sending sensitive prompts, queries, URLs, or page content to external services.
- Run the CLI with least privilege and restrict its filesystem, environment-variable, credential, and network access where feasible.
- Establish a controlled update process requiring renewed source review and integrity verification before changing the pinned version.
- Pin
