T08 · Insecure Dependencies
- Location
scripts/remotion.sh:10- Finding
Execution of Unpinned npm Packages Through npx
- Content
View full analysis
Vulnerability Details
File Location:
scripts/remotion.sh:8-10
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: HighVulnerable Code:
bash init) PROJECT_NAME="${1:?init <name>}" npx --yes create-video@latest "$PROJECT_NAME" ;;Technical Analysis
The script invokes
create-video@latestthroughnpx --yes. Thelatesttag is mutable and does not identify a specific reviewed package version or integrity hash. The--yesoption suppresses the interactive installation prompt, allowing npm to download and execute the currently published package without user confirmation.An npm package executed through
npxmay run its command-line entry point and installation lifecycle scripts with the privileges of the user running the skill. Consequently, the effective code executed by this reviewed script can change after the audit if the package is compromised, transferred to a malicious maintainer, or receives an unsafe release.The same script also invokes
npx remotion renderat line 21. If Remotion is unavailable locally,npxmay resolve and download a package dynamically rather than using a known, locked dependency.Attack Path
- An attacker compromises the
create-videonpm package, its maintainer account, or its release process. - The attacker publishes a malicious version under the mutable
latesttag. - A user or agent invokes
scripts/remotion.sh init. npx --yesdownloads the malicious package without an interactive confirmation.- npm executes the package entry point or applicable lifecycle scripts.
- The malicious package executes arbitrary commands under the invoking user's account.
Impact Assessment
Successful exploitation provides arbitrary code execution with the permissions of the account running the skill. The malicious dependency could read or alter accessible project files, environment variables, source-code cr ...[truncated 295 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace mutable tags such as
latestwith an exact, reviewed version. - Declare the required tooling in a committed
package.jsonand lock it withpackage-lock.json. - Install dependencies using
npm ciso resolution is reproducible and fails when the lockfile is inconsistent. - Execute the locked local binary, such as
npx --no-install create-video, rather than permitting dynamic downloads. - Use
npx --no-install remotion renderfor rendering and fail if the expected local package is absent. - Review npm provenance and integrity metadata before version updates.
- Disable package lifecycle scripts where compatible with the toolchain, or perform installation in an isolated environment with minimal filesystem access, credentials, and network permissions.
- Replace mutable tags such as
