T08 · Insecure Dependencies
- Location
SKILL.md:159- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:159-160
Vulnerability Type: Supply-chain risk from unpinned package retrieval and execution
Risk Level: MediumVulnerable Code:
bash npx husky install npx husky add .git/hooks/pre-commit "npm run lint"Technical Analysis
The documented commands invoke
huskythroughnpxwithout specifying an exact, reviewed version or requiring an already-installed local dependency. If Husky is not available locally,npxmay retrieve the package from the configured package registry and execute it immediately.Consequently, the code executed by these commands is not fully determined by the reviewed Skill text. Package updates, registry compromise, unsafe registry configuration, or dependency-resolution manipulation could cause an unexpected package version to run with the invoking user's permissions. Package lifecycle scripts and the CLI itself may execute arbitrary code. The commands are also intended to alter Git hook configuration, which can cause code to run during later Git operations.
Attack Path
- A user follows the instructions in
SKILL.mdto install Git hooks. - The requested
huskyexecutable is not present in the project's local dependencies. npxresolves and downloads a package from the user's configured package registry without enforcing a reviewed version.- A compromised, substituted, or unexpectedly changed package executes its lifecycle or CLI code under the user's account.
- The package can access resources available to that process and may modify the repository or its Git hook configuration.
- Malicious hook content could subsequently execute when affected Git operations occur.
Impact Assessment
Successful exploitation would provide code execution with the permissions of the user running
npx. The accessible scope may include the current repository, writable files available to that user, environment variables ...[truncated 345 chars]- A user follows the instructions in
- Remediation
View remediation
Remediation Suggestions
- Declare Husky as a development dependency using an audited, exact version.
- Commit the package manifest and lockfile, and install dependencies with
npm ci. - Invoke only the locally installed package, such as with
npx --no-install husky, or use a package-manager script that resolves the locked local binary. - Configure CI to reject unexpected lockfile changes and use dependency integrity verification.
- Review all generated or modified Git hooks before enabling them.
- Regularly scan the locked dependency tree and apply updates through a controlled review process.
