T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:30
Vulnerability Type: Insecure dependency installation
Risk Level: MediumVulnerable Code
bash npx clawhub@latest install chinese-content-generatorTechnical Analysis
The documented installation command instructs users to download and execute the mutable
latestrelease of the third-partyclawhubpackage. No exact version, package integrity hash, signature verification, or lockfile constrains the code thatnpxwill execute.Consequently, the effective installation code can change after this Skill has been audited. This creates a supply-chain trust gap: a compromised package publisher, registry account, package release, or upstream distribution channel could cause users following the documentation to execute code that was not part of the reviewed project.
This finding does not establish that the current
clawhubpackage is malicious. The risk arises from executing a mutable, externally supplied dependency without pinning or verification.Attack Path
- An attacker compromises the upstream package publisher, registry account, release process, or another relevant distribution component.
- The attacker publishes a malicious release that becomes the package's
latestversion. - A user follows the installation command in
SKILL.md. npxretrieves and executes the attacker-controlled package release.- The malicious package runs with the privileges and environment available to the user performing the installation.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the installing user's account. Depending on that user's privileges and environment, the malicious dependency could access readable local files and credentials, alter user-owned configuration, install additional components, or make network requests.
The immediate privilege level is normally that of the user invoking
npx; ...[truncated 214 chars]- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version:bash npx clawhub@<audited-exact-version> install chinese-content-generator - Document the expected package registry and publisher identity so namespace or registry substitution is easier to detect.
- Verify package provenance through supported registry signatures, attestations, or an independently published checksum before execution.
- Use a lockfile and integrity metadata where the installation workflow supports them.
- Review each dependency update before changing the pinned version.
- Advise users not to run the installer with administrator or root privileges unless strictly necessary.
- Replace
