T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Mutable npm Package Executed Through the @latest Tag
- Content
View full analysis
--json npx @openant-ai/cli@latest tasks unassign --json ``` ### Technical Analysis The Skill invokes an npm package through `npx` while selecting its version with the mutable `@latest` distribution tag. Consequently, the code executed during future Skill invocations is not necessarily the code that existed when the Skill was reviewed. Depending on the local npm cache and `npx` configuration, the command may retrieve and execute a package release directly from the npm registry. A malicious or compromised future release could therefore execute arbitrary package lifecycle or CLI code with the privileges and environment of the Agent process. This creates a supply-chain trust boundary outside the audited project. The repository does not pin an exact package version, provide a lockfile or integrity hash, or include the dependency implementation for review. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or the associated release process. 2. The attacker publishes a malicious package version and causes the `latest` tag to reference it. 3. A user asks the Agent to perform an operation covered by this Skill. 4. The Agent runs a documented command such as `npx @openant-ai/cli@latest status --json`. 5. `npx` retrieves and executes the attacker-controlled package version. 6. The package executes with the local privileg ...[truncated 1066 chars]- Remediation
View remediation
status --json ``` 2. Prefer installing the audited dependency during a controlled build or deployment phase rather than downloading executable code whenever the Skill runs. 3. Commit a lockfile that records the complete transitive dependency graph and integrity metadata. 4. Enforce registry and integrity verification in CI/CD, and reject unexpected package or lockfile changes. 5. Review package lifecycle scripts and transitive dependencies before approving version upgrades. 6. Run the CLI with least privilege in a sandboxed environment, exposing only the files, network destinations, environment variables, and narrowly scoped OpenAnt credentials required for the requested operation. 7. Update the `allowed-tools` entries and every command in `SKILL.md` consistently so no invocation can continue to select the mutable `latest` release. ]]>
