T08 · Insecure Dependencies
- Location
README.md:8- Finding
Unpinned Third-Party Installer Execution in English Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 7-9
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code:
bash npx skills add alondotsh/alon-skills --skill alon-search-skill-plusTechnical Analysis
The documented installation command invokes the third-party
skillsnpm package throughnpxwithout specifying an exact package version or verifying its integrity. If the package is unavailable locally,npxcan retrieve its current release from the configured npm registry and execute its command-line entry point.Consequently, the code executed during installation is mutable and may differ from the code reviewed during this audit. The command also directs the installer to retrieve skill content from the external
alondotsh/alon-skillsrepository without pinning that content to an audited commit. This creates a supply-chain trust dependency on both the npm package and the referenced repository.Attack Path
- An attacker compromises the npm account, package publishing process, registry resolution path, or referenced repository.
- The attacker publishes a malicious release or modifies the remotely retrieved skill content.
- A user follows the documented Quick Install command.
npxresolves and executes the mutable package release, which retrieves the current external skill content.- Malicious installer behavior executes with the permissions of the user running the command.
Impact Assessment
A compromised installer could execute commands with the invoking user's privileges. Depending on those privileges and the malicious payload, this could expose accessible files, environment variables, tokens, source repositories, and application data, or modify user-owned files and development configuration. System-wide impact would require the command to be run with elevated privileges or a separate privilege-escalation flaw.
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm package to an exact, reviewed version rather than allowingnpxto resolve the latest release. - Pin the installed skill source to an audited commit hash or immutable release tag where the installer supports it.
- Document the expected npm publisher, source repository, and package provenance so users can verify them before execution.
- Provide checksums, signatures, or registry integrity information for reviewed releases.
- Offer a manual installation procedure that downloads a pinned revision for inspection before any installer code is executed.
- Advise users not to run the installation command with administrative privileges.
- Pin the
