Known Vulnerable Dependency: fs==0.0.1-security — 1 advisory(ies): MAL-2025-21003 (Malicious code in fs (npm))
High
- Category
- Supply Chain
- Confidence
- 99% confidence
- Finding
- The lockfile pins the package `fs@0.0.1-security`, and the provided advisory identifies it as a malicious npm package. A malicious dependency in the supply chain can execute attacker-controlled code during install or runtime, potentially leading to credential theft, file tampering, or arbitrary code execution in environments that build or run this skill.
