T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Third-Party Dependency Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–78
Vulnerability Type: Uncontrolled installation and execution of mutable third-party dependencies
Risk Level: MediumVulnerable Code
bash npm install -D vitest @testing-library/react @testing-library/jest-dom npx vitest npx vitest run npx vitest --coveragebash npm install -D jest @types/jest ts-jest npx jest npx jest --watch npx jest --coverage npx jest path/to/testbash uv pip install pytest pytest-cov pytest-asyncio httpx pytest pytest -v pytest -x pytest --cov=app pytest tests/test_api.py -k "test_login" pytest --tb=shortbash npm install -D @playwright/test npx playwright install npx playwright test npx playwright test --headed npx playwright test --debug npx playwright test --project=chromium npx playwright show-reportTechnical Analysis
The skill instructs an agent to install packages without exact version pins, lockfile enforcement, package-integrity validation, registry restrictions, or explicit user approval. Package names consequently resolve to mutable releases available from the configured package registry at execution time.
Package installation can execute lifecycle scripts with the permissions of the agent process. In addition,
npxmay download and execute a package dynamically if a trusted local executable is unavailable. Thenpx playwright installcommand also retrieves browser executables after package installation. These behaviors create a supply-chain execution boundary that is not controlled by the reviewed skill content.There is no evidence that the named packages are currently malicious or that the skill intentionally selects a typosquatted package. The vulnerability is the unsafe dependency acquisition and execution procedure, which could expose users to a compromised package release, registry substitution, dependency confusion in a manipul ...[truncated 1837 chars]
- Remediation
View remediation
Remediation Suggestions
- Require explicit user approval before installing any new package, browser binary, or other executable component.
- Prefer the project's existing test framework, lockfile, package scripts, and locally installed executables.
- Pin dependencies to exact, reviewed versions rather than unconstrained package names.
- For npm projects, use a committed lockfile and
npm cirather than generating new dependency resolutions withnpm install. - Invoke tools through verified project scripts or explicitly local binaries, and prevent
npxfrom downloading missing packages, for example by usingnpx --no-installwhere supported. - For Python projects, install from a reviewed requirements or lock file containing exact versions and cryptographic hashes.
- Restrict package managers to approved registries and verify that project-level configuration cannot silently redirect dependency resolution.
- Disable package lifecycle scripts where compatible with the selected framework, then explicitly run only reviewed setup operations.
- Run installation and tests in an isolated environment with minimal filesystem permissions, no unnecessary credentials, and restricted outbound network access.
- Treat Playwright browser downloads as executable dependency acquisition: pin the Playwright version, verify download provenance and integrity, and obtain approval before installation.
