T08 · Insecure Dependencies
- Location
README.md:7- Finding
Unpinned Third-Party Installers and Mutable Sources Permit Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill is a disclosed Uniswap opportunity-scanning helper, but users should treat its financial outputs as research and be careful with the unpinned install commands.
Install through a trusted, reviewed ClawHub flow when possible, avoid running unpinned npx commands with elevated privileges, and verify the source before using README install commands. Treat scan results as leads for further research, not guaranteed returns or personalized financial advice.
README.md:7Unpinned Third-Party Installers and Mutable Sources Permit Supply-Chain Code Execution
The README instructs users to run npx skills add without pinning a specific package version, which means the installer will fetch the latest published code at execution time. If the upstream package is compromised, maliciously updated, or subject to a dependency-chain attack, users could execute unreviewed code on their system during installation.
The command npx clawhub@latest install scan-opportunities explicitly tracks the latest version, causing users to execute whatever code is current in the registry at install time. This increases supply-chain risk because a malicious release, account compromise, or typo/dependency attack could turn the installation step into arbitrary code execution.
The description uses broad phrases like 'best opportunities' and 'high-yield pools,' which can cause the skill to activate on general investment questions outside a narrowly intended scanning workflow. Over-broad invocation increases the chance the agent routes users into financial-opportunity recommendations without sufficient gating, context checks, or clearer user intent confirmation.
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
---
name: scan-opportunities
description: Scan for LP opportunities, arbitrage, and high-yield pools across all Uniswap deployments. Use when the user asks about the best opportunities, high-yield pools, or arbitrage.
model: opus
allowed-tools: [Task(subagent_type:opportunity-scanner)]
---
The trigger examples are vague and open-ended, such as 'Where should I LP?' and 'What are the best opportunities right now?', without boundaries or disambiguation rules. This makes invocation overly permissive and can cause the skill to handle broad portfolio or investment-advice requests that may exceed the intended scope of a market-scanning tool.
No suspicious patterns detected.