T08 · Insecure Dependencies
- Location
SKILL.md:47- Finding
Unpinned Third-Party Automation Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:47-50; related dependency declarations inpackage.json:10-16
Vulnerability Type: Unpinned and insufficiently verified third-party dependencies
Risk Level: MediumThe Skill directs users to install six external automation components without pinning reviewed versions, verifying package integrity, or validating trusted publishers.
Vulnerable code in
SKILL.md:47-50:powershell If any dependencies are missing, run: clawhub install windows-ui-automation win-mouse-native windows-desktop-control midscene-computer-automation windows-screenshot windows-rpaRelated declarations in
package.json:10-16:json "peerDependencies": { "windows-ui-automation": ">=1.0.0", "win-mouse-native": ">=1.0.0", "windows-desktop-control": ">=1.0.0", "midscene-computer-automation": ">=1.0.0", "windows-screenshot": ">=1.0.0", "windows-rpa": ">=1.0.0" }Technical Analysis
The installation command resolves dependencies from an external package registry without specifying exact versions or integrity hashes. The corresponding
peerDependenciesconstraints use open-ended>=1.0.0ranges, allowing any future compatible or incompatible release above that version to satisfy the requirement.This creates a supply-chain risk because the code ultimately executed may differ from the code reviewed when this Skill was published. Exploitation would require compromise or malicious publication of one of the named dependencies, package ownership takeover, registry compromise, or another package-resolution failure. No evidence in the audited files establishes that any current dependency is malicious.
The risk is amplified by the dependencies' intended capabilities. They provide desktop control, native mouse input, UI automation, screenshots, visual analysis, and RPA functions. Consequently, a compromised dependency could act through a high-impact inter ...[truncated 1594 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every dependency to a specific version that has undergone security review rather than using open-ended
>=constraints. - Include exact versions in the documented installation command where the package manager supports that syntax.
- Record and verify cryptographic integrity hashes, signed package metadata, or registry provenance before installation.
- Verify and document the trusted publisher identity for each dependency.
- Establish a controlled upgrade process requiring source review, behavioral testing, and renewed integrity metadata before changing pinned versions.
- Audit each downstream Skill independently, especially its scripts, installation hooks, network behavior, screenshot handling, and use of desktop permissions.
- Run automation under a dedicated least-privileged account and avoid administrator execution unless a specific workflow requires it.
- Restrict access to sensitive windows and data during automation sessions, and require user confirmation before security-sensitive GUI actions.
- Pin every dependency to a specific version that has undergone security review rather than using open-ended
