T08 · Insecure Dependencies
- Location
references/orchestration.md:15- Finding
Unpinned Third-Party Package Is Downloaded and Executed Through npx
- Content
View full analysis
" --format json ``` The same unpinned package is invoked for page audits: ```bash npx @ainyc/aeo-audit "" --format json npx @ainyc/aeo-audit "" ``` ### Technical Analysis The documented workflows invoke `@ainyc/aeo-audit` through `npx` without specifying an exact package version, integrity hash, lockfile, or trusted local installation. If the package is not already installed, `npx` can retrieve the latest matching version from the configured npm registry and execute it immediately. This creates a supply-chain risk because the effective executable can change after this Skill has been reviewed. A compromised publisher account, malicious package release, registry compromise, or unsafe registry configuration could cause arbitrary package lifecycle scripts or runtime code to execute under the agent operator's account. Although no malicious dependency is bundled in this project, the documented execution method does not provide reproducible or integrity-verified dependency resolution. ### Attack Path 1. An attacker compromises the npm publisher account, package distribution process, or registry used to resolve `@ainyc/aeo-audit`. 2. The attacker publishes a malicious package version under the expected package name. 3. An operator or agent follows one of the workflows in `references/orchestration.md`. 4. `npx` resolves and downloads the mutable package version because no exact version or local-only restriction is specified. 5. Package lifecycle scripts or application code execute with the privileges of the user running the workflow. 6. The malicious code can access files, environment variables, locally available credentials, and network resources permitted to that user. ### Impact Assessme ...[truncated 672 chars]- Remediation
View remediation
"" --format json ``` 2. Prefer installing the dependency through a committed lockfile that records package integrity metadata. 3. Run the already installed binary with `npx --no-install` so the workflow fails rather than downloading an unexpected package: ```bash npx --no-install aeo-audit "" --format json ``` 4. Configure npm to use an explicitly trusted registry and review project-level and user-level npm configuration for registry overrides. 5. Verify package provenance, publisher ownership, release signatures where available, and integrity hashes before upgrades. 6. Execute the audit package in a restricted environment with minimal filesystem access, sanitized environment variables, and limited network permissions. 7. Apply the same hardened invocation to all occurrences at lines 15, 29, and 55. ]]>
