T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Global npm Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–26 and 31–40
Vulnerability Type: Insecure third-party dependency installation
Risk Level: MediumVulnerable Code
markdown ## Prerequisites - Node.js 18+ - `npm install -g kbo-game`markdown ### 0. Install the package globally when missing `npm root -g` 아래에 `kbo-game` 이 없으면 다른 구현으로 우회하지 말고 전역 Node 패키지 설치를 먼저 시도한다. ```bash npm install -g kbo-gametext ### Technical Analysis The skill instructs the agent to install `kbo-game` from the npm registry globally without specifying an exact version or verifying package integrity. Consequently, the installed code can differ between executions as new releases are published. An npm installation may execute package lifecycle scripts such as `preinstall`, `install`, and `postinstall`. Installing globally also increases the affected scope compared with an isolated, project-local dependency. The document later dynamically imports and executes the installed package, further placing trust in registry-delivered code. This is a supply-chain exposure rather than evidence that the current `kbo-game` package is malicious. Exploitation requires compromise or hostile modification of the package, its publisher account, or the relevant package-delivery infrastructure. ### Attack Path 1. An attacker compromises the `kbo-game` package, its publisher account, or its release process. 2. The attacker publishes a malicious version under the same package name. 3. An agent follows `SKILL.md` and runs `npm install -g kbo-game` without a version or integrity constraint. 4. npm retrieves the attacker-controlled release. 5. Malicious lifecycle scripts may execute during installation. 6. The workflow subsequently imports `dist/index.js`, providing another opportunity for attacker-controlled code to execute. 7. The code runs with the permissions of the account executing npm and can affect resources accessible to that account. ### Impact Assessment Su ...[truncated 576 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the package to a reviewed exact version, for example
kbo-game@0.0.2, rather than resolving the latest available release. - Install the dependency locally in an isolated project directory instead of modifying the global Node.js environment.
- Commit and enforce a lockfile containing registry integrity metadata, and use
npm cifor reproducible installation. - Review the pinned package, its transitive dependencies, and any lifecycle scripts before deployment.
- Use
--ignore-scriptswhen lifecycle scripts are unnecessary and compatibility testing confirms that the package still operates correctly. - Run installation and execution as a dedicated, unprivileged user in a sandbox or container with minimal filesystem and network access.
- Restrict dependency retrieval to an approved registry or internal mirror and apply package allowlisting and provenance verification where available.
- Import only the locally pinned dependency and fail closed if its version or integrity does not match the approved values.
- Pin the package to a reviewed exact version, for example
