T08 · Insecure Dependencies
- Location
README.md:64- Finding
Unpinned Third-Party Packages Are Installed or Executed Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
README.md:64-98and duplicated installation instructions atREADME.md:226-262
Vulnerability Type: Unpinned and mutable third-party npm dependencies
Risk Level: MediumVulnerable Code
bash npm install -g @jackwener/openclibash claude mcp add playwright --scope user -- npx @playwright/mcp@latestbash npx skills add joeseesun/opencli-skillTechnical Analysis
The documented installation process installs or executes third-party npm packages without immutable version pins or integrity verification. The use of
@latestexplicitly resolves to a mutable future release, while the other commands rely on the registry's current package resolution.The
npm install -gcommand installs a package globally. The Playwright MCP command executes a transient package throughnpxand registers the resulting MCP configuration at user scope. The skill installation command also invokes code resolved throughnpx. Consequently, installation behavior can change after this skill has been reviewed without any change to the files in this repository.This is a supply-chain exposure rather than evidence that the currently referenced packages are malicious. Exploitation would require compromise of a package, one of its transitive dependencies, its publisher account, or the package-resolution infrastructure.
Attack Path
- An attacker compromises a referenced npm package, publisher account, transitive dependency, or registry resolution path.
- The attacker publishes a malicious version under a package name used by the documented commands.
- A user follows the installation or troubleshooting instructions.
- npm or
npxresolves the mutable package reference to the compromised release. - Package lifecycle scripts or the resolved executable run with the user's operating-system privileges.
- Malicious code can access resources available to that ...[truncated 1080 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every referenced npm package to an exact, reviewed version rather than using an implicit current version or
@latest. - Replace the mutable MCP invocation with an exact version, for example:
bash claude mcp add playwright --scope user -- npx @playwright/mcp@<reviewed-exact-version> - Pin
@jackwener/opencliand the skill installer workflow to reviewed releases. - Publish expected package versions, provenance information, and integrity hashes in the installation documentation.
- Where supported, require npm provenance or signature verification before installation.
- Prefer a project-local, lockfile-controlled installation over global installation and transient
npxexecution. - Disable or strictly limit lifecycle scripts during installation where operationally possible, and review any scripts before enabling them.
- Run browser-control components under a dedicated low-privilege account or isolated browser profile containing only the sessions required for the task.
- Document the permissions granted to the MCP component and provide removal procedures for the user-scoped registration.
- Periodically audit pinned packages and transitive dependencies, updating them only after review.
- Pin every referenced npm package to an exact, reviewed version rather than using an implicit current version or
