T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Third-Party Package Execution via ClawHub Installer
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:16
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: MediumVulnerable Code:
bash npx clawhub@latest install 10x-patternsTechnical Analysis
The installation instructions invoke
clawhubthroughnpxusing the mutablelatesttag. Annpxinvocation can download and execute npm package code, including package entry points and lifecycle scripts, with the privileges of the current user.Because
latestdoes not identify an immutable, reviewed release, the code executed by this command can change after the Skill itself has been audited. Compromise of the package, publisher account, npm distribution channel, or a future malicious release could therefore turn this documented installation command into an arbitrary code-execution path.The repository does not include or constrain the remotely resolved package and does not provide a version pin, integrity hash, or signature that would allow users to verify the downloaded artifact.
Attack Path
- An attacker compromises the
clawhubpackage, its publisher account, or the relevant package-distribution process. - The attacker publishes a malicious release and assigns or causes it to receive the
latesttag. - A user follows the documented installation command.
npxresolves and downloads the attacker-controlled package version.- Package or lifecycle code executes in the user's environment.
- The malicious code can perform actions available to the invoking user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. The accessible scope may include source repositories, user-readable files, development credentials, environment variables, SSH configuration, package-manager tokens, and any services reachable with the user's existing permissions.
This command does not itself request ...[truncated 361 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith a specific, reviewed package version. - Where supported, verify the package against a published integrity hash or cryptographic signature.
- Use a lockfile or equivalent mechanism to preserve the reviewed dependency resolution.
- Document the expected package publisher, version, checksum, and provenance.
- Prefer an installation process that downloads content for inspection before executing it.
- Re-audit the pinned artifact whenever the version is updated.
- Avoid running the installer with administrative privileges and use an isolated environment where practical.
- Replace
