T08 · Insecure Dependencies
- Location
README.md:81- Finding
Unpinned ClawHub CLI execution through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md:81-92
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
bash npx clawhub login npx clawhub publish skills/daily-tech-broadcast --slug daily-tech-broadcast --name "每日科技播报" --version 1.0.0 --changelog "Initial release: 新浪科技/IT之家抓取,无需 API Key" npx clawhub publish . --slug daily-tech-broadcast --name "每日科技播报" --version 1.0.0 --changelog "Initial release"Technical Analysis
The documentation instructs users to execute the
clawhubnpm package throughnpxwithout specifying a package version or integrity value. If the package is not already installed locally,npxmay retrieve and execute the current registry release.Consequently, the code that runs is not fixed to the package version reviewed when this Skill was published. A compromised package, registry account, dependency, or unexpectedly incompatible future release could execute arbitrary installation or runtime code. These commands are publisher-oriented operations and are not necessary for the Skill's declared runtime function of downloading public news headlines.
Attack Path
- An attacker compromises the
clawhubpackage, one of its dependencies, or the relevant package-publishing account. - A malicious version is published under the package name referenced by the README.
- A user follows the documentation and runs an unversioned
npx clawhubcommand. npxdownloads the compromised release when no trusted local copy is available.- Package installation or execution code runs with the privileges of the invoking user.
Impact Assessment
Successful exploitation could run arbitrary code with the invoking user's operating-system privileges. Depending on that user's access, the malicious package could read workspace files and user-accessible credentials, alter source code, access authenticated development tooling, or make outb ...[truncated 168 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specific reviewed version, such as
npx clawhub@<reviewed-version>. - Use a lockfile and verify package integrity before execution.
- Prefer a separately installed, organization-approved CLI rather than allowing
npxto download code on demand. - Document the expected package publisher, version, checksum, and verification procedure.
- Move publishing instructions into maintainer documentation so ordinary Skill users are not encouraged to execute unnecessary package-management commands.
- Run publishing tools in a restricted environment without access to unrelated credentials or sensitive workspace files.
- Pin the CLI to a specific reviewed version, such as
