T08 · Insecure Dependencies
- Location
scripts/publish.sh:19- Finding
Automatic Global Installation of an Unpinned Third-Party Dependency
- Content
View full analysis
/dev/null; then echo -e "${RED}❌ wenyan-cli 未安装!${NC}" echo -e "${YELLOW}正在安装 wenyan-cli...${NC}" npm install -g @wenyan-md/cli if [ $? -eq 0 ]; then echo -e "${GREEN}✅ wenyan-cli 安装成功!${NC}" else echo -e "${RED}❌ 安装失败!请手动运行: npm install -g @wenyan-md/cli${NC}" exit 1 fi fi } ``` ### Technical Analysis The publishing script automatically runs `npm install -g @wenyan-md/cli` when it cannot find a `wenyan` executable. The dependency is referenced without an exact version, lockfile, or integrity constraint. Consequently, the code installed depends on the package and dependency versions available from the configured npm registry at execution time rather than the versions reviewed with this Skill. npm installation can execute package lifecycle scripts. A compromised package release, compromised transitive dependency, registry takeover, or maliciously configured npm registry could therefore result in arbitrary local code execution. The global installation flag also modifies the user's global Node.js environment and may require elevated privileges on some systems. The installation occurs as an implicit side effect of invoking the publishing workflow. The script does not request confirmation, display the resolved version, validate package integrity, or constrain lifecycle scripts. ### Attack Path 1. A user invokes `scripts/publish.sh` on a system where `wenyan` is not installed or is not available through `PATH`. 2. The script automatically contacts the npm registry configured on the system. 3. npm resolves the latest available release of `@wenyan-md/cli` and its transitive dependencie ...[truncated 1037 chars]- Remediation
View remediation
