T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Execution of an Unpinned Remote npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 5-27
Vulnerability Type: Supply-chain risk caused by mutable dependency execution
Risk Level: HighVulnerable Code
yaml allowed-tools: ["Bash(npx @openant-ai/cli@latest status*)", "Bash(npx @openant-ai/cli@latest login*)", "Bash(npx @openant-ai/cli@latest verify*)", "Bash(npx @openant-ai/cli@latest agents *)", "Bash(npx @openant-ai/cli@latest setup-agent*)", "Bash(npx @openant-ai/cli@latest bind-email*)", "Bash(npx @openant-ai/cli@latest config *)"]bash npx @openant-ai/cli@latest status --jsonbash npx @openant-ai/cli@latest login --key --name "MyAgent" --role AGENT --jsonTechnical Analysis
The Skill consistently invokes
@openant-ai/clithrough the mutable npm taglatest. The package version and package integrity are not pinned in the Skill, so the code executed at invocation time may differ from the code that existed when the Skill was reviewed.npxcan retrieve and execute a package from the npm registry when the required package version is not already available locally. Consequently, compromise of the publisher account, npm package, distribution pipeline, or a future malicious release could turn otherwise legitimate status, login, registration, or configuration commands into arbitrary local code execution.The risk is amplified because the CLI is intentionally used to create or reuse cryptographic keys under
~/.openant/keys/, authenticate the Agent, and modify its OpenAnt configuration.Attack Path
- An attacker compromises the npm publisher account, release pipeline, or package associated with
@openant-ai/cli. - The attacker publishes a malicious version and assigns it to the
latesttag. - A user invokes this Skill for status checking, authentication, or Agent registration.
npx @openant-ai/cli@latestresolves and downloads the attacker-controlled release.- npm executes the packa ...[truncated 1063 chars]
- An attacker compromises the npm publisher account, release pipeline, or package associated with
- Remediation
View remediation
Remediation Suggestions
- Replace every use of
@latestwith a specific, audited package version, for example:bash npx --yes @openant-ai/cli@X.Y.Z status --json - Verify the package tarball against an expected integrity hash before execution.
- Manage the CLI through a lockfile and a controlled installation process rather than downloading executable code during each Skill invocation.
- Review and approve version upgrades explicitly instead of following a mutable distribution tag.
- Run the CLI in a least-privileged environment with narrowly scoped filesystem and network access.
- Protect
~/.openant/keys/with restrictive file permissions and prevent unrelated package lifecycle scripts from accessing it where sandboxing is available. - Consider disabling npm lifecycle scripts during controlled installation when they are not required.
- Replace every use of
