T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party CLI Installation Enables Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25–35
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: HighVulnerable Code
yaml requires: bins: [meta] install: - id: bun kind: command command: "bun install -g meta-business-cli" bins: [meta] label: "Install meta CLI (bun)" - id: compile kind: command command: "git clone https://github.com/adolago/meta-cli.git && cd meta-cli && bun install && bun build --compile --outfile ~/.bun/bin/meta src/index.ts" bins: [meta] label: "Build from source (standalone binary)"Technical Analysis
Both installation methods retrieve mutable third-party content without pinning an exact package version, immutable Git commit, dependency lockfile state, or cryptographic integrity value.
The first method installs the currently resolved release of
meta-business-cli. The second clones the current default branch of an external repository, installs its transitive dependencies, compiles the fetched source, and writes the resulting executable to~/.bun/bin/meta. Consequently, the code executed by users can differ from the code available when this Skill was reviewed.The project contains only
SKILL.md; it does not include the CLI source or its dependency tree. The audit therefore cannot verify package lifecycle scripts, build behavior, credential storage, network destinations, or runtime handling of Meta account data.Attack Path
- An attacker compromises the package registry entry, upstream repository, maintainer account, release process, or a transitive dependency.
- The attacker publishes malicious code under the same package name or places it on the repository’s mutable default branch.
- A user installs the Skill dependency through either documented installation command.
bun installexecutes dependency installation logic, or the sourc ...[truncated 1003 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
meta-business-clito an explicitly reviewed version rather than resolving the latest available release. - Pin source installations to a full immutable Git commit hash and verify that the commit belongs to an authenticated release.
- Commit and enforce a dependency lockfile using frozen or immutable installation mode.
- Publish expected cryptographic checksums or signatures for the package and compiled binary, and verify them before execution.
- Disable dependency lifecycle scripts where feasible, or audit every required lifecycle script before allowing it to run.
- Build the executable in an isolated, least-privileged environment without access to user credentials.
- Prefer distributing a reproducible, signed artifact generated from audited source.
- Review and update the pinned dependency deliberately instead of automatically consuming mutable upstream content.
- Pin
