T08 · Insecure Dependencies
- Location
references/skill-security-checklist.md:599- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
references/skill-security-checklist.md:599
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash npx eslint scripts/ --plugin securityTechnical Analysis
The security checklist recommends invoking ESLint through
npxwithout requiring a reviewed local installation, pinned package versions, a lockfile, or integrity verification.When the requested executable is unavailable locally,
npxmay obtain and execute a package from the configured npm registry. The code ultimately executed during an audit can therefore differ from the code reviewed with this Skill. This creates a supply-chain boundary in a security-sensitive workflow.An attacker would need to compromise a resolved package, its maintainer or registry distribution path, or influence package resolution or registry configuration. The issue does not establish that the referenced packages are malicious; the risk arises from allowing mutable third-party code to execute without pinning and verification.
Attack Path
- An agent follows the documented automated security-scanning procedure.
- The required executable or plugin is not present in the local project.
npxresolves dependencies through the configured npm registry.- A compromised package release, dependency, registry account, or resolution path supplies attacker-controlled code.
- Package installation behavior or the resolved executable runs under the auditing process's identity.
- The malicious code accesses resources available to that process, potentially including repository files, environment variables, credentials, and network access.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user or agent running the audit. The accessible scope depends on the surrounding sandbox and may include:
- Read or modification access to the audited repository.
- Ac ...[truncated 417 chars]
- Remediation
View remediation
Remediation Suggestions
- Declare reviewed versions of
eslintandeslint-plugin-securityas development dependencies and pin them through a committed lockfile. - Install dependencies deterministically in an isolated environment:
bash npm ci --ignore-scripts - Invoke only the verified local executable:
bash ./node_modules/.bin/eslint scripts/ - Prevent automatic remote package acquisition, for example by using an
npxmode that refuses installation where supported. - Verify lockfile integrity and review dependency provenance before execution.
- Run scanners in a sandbox with read-only repository access where practical, no unnecessary secrets in the environment, restricted outbound networking, and no administrative privileges.
- Document the exact scanner and plugin versions required by the Skill.
- Declare reviewed versions of
