T08 · Insecure Dependencies
- Location
scripts/package-lock.json:419- Finding
Third-Party Wallet SDK Executes an Installation Lifecycle Script
- Content
View full analysis
=16.0.0" } } ``` The installation instruction is: ```bash cd skills/hyperliquid/scripts && npm install ``` The installed SDK is subsequently given the trading private key: ```js const privateKey = process.env.HYPERLIQUID_PRIVATE_KEY; const sdk = new Hyperliquid({ privateKey: privateKey || undefined, testnet: isTestnet, enableWs: false, }); ``` ### Technical Analysis The `hyperliquid` dependency declares `hasInstallScript: true`. Therefore, following the documented `npm install` procedure executes third-party lifecycle code with the privileges of the user installing the Skill. The package is resolved from the official npm registry and protected by a lockfile integrity hash, which reduces accidental substitution and network tampering. However, these controls do not eliminate the trust boundary: a malicious or compromised dependency release can intentionally contain harmful lifecycle or runtime behavior. This is especially sensitive because the package is later instantiated with `HYPERLIQUID_PRIVATE_KEY`, granting its runtime code access to wallet signing authority. No malicious lifecycle implementation or credential exfiltration was demonstrated in the audited project. The finding concerns the unsafe ins ...[truncated 1396 chars]- Remediation
View remediation
