T08 · Insecure Dependencies
- Location
SKILL.md:82- Finding
Automatic Execution of Unreviewed Dependency and Build Scripts
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 82–90
Vulnerability Type: Automatic installation and execution of repository-controlled dependencies
Risk Level: MediumVulnerable Code
bash # Node.js if [ -f package.json ]; then npm install; fi # Python if [ -f requirements.txt ]; then pip install -r requirements.txt; fi if [ -f pyproject.toml ]; then pip install -e .; fi # Rust if [ -f Cargo.toml ]; then cargo build; fi # Go if [ -f go.mod ]; then go mod download; fiTechnical Analysis
The skill instructs the agent to detect dependency manifests and automatically invoke package managers or build systems without first reviewing the dependencies or obtaining explicit user approval.
Several of these operations can execute code controlled by the repository or its dependencies:
npm installcan run package lifecycle scripts, includingpreinstall,install, andpostinstall.pip install -e .can invoke repository-selected Python build backends and execute package build or installation logic.pip install -r requirements.txtinstalls packages from sources specified by the repository and does not require hashes or a lockfile.cargo buildexecutes Rust build scripts declared throughbuild.rs.- Dependency resolution without an enforced lockfile or integrity policy can retrieve versions that were not reviewed when the skill was audited.
The skill does not require version pinning, integrity verification, script suppression, source allowlisting, sandboxing, or confirmation before these commands execute. Consequently, workspace initialization can become an arbitrary code-execution channel if the skill is invoked in a malicious or compromised repository.
Attack Path
- An attacker creates or compromises a repository in which one of the detected manifest files is present.
- The attacker adds a malicious package lifecycle script, Python build backend, Rust build script, or dependency reference.
- A user ...[truncated 1334 chars]
- Remediation
View remediation
Remediation Suggestions
- Separate isolated branch creation from dependency installation and make dependency setup an explicit optional phase.
- Present the exact command to the user and require confirmation before invoking a package manager or build system.
- Prefer deterministic, lockfile-enforced installation:
- Use
npm ciwith a reviewedpackage-lock.json. - Require hash-pinned Python requirements, such as
pip install --require-hashes -r requirements.txt. - Use Cargo and Go lockfiles where applicable and enforce locked resolution.
- Use
- Disable lifecycle scripts where compatible with the project, such as using
npm ci --ignore-scripts, and enable scripts only after review. - Review Python build-system declarations and Rust
build.rsfiles before executing editable installations or builds. - Restrict package sources to approved registries and avoid untrusted direct URLs, Git dependencies, or custom indexes.
- Run installation and build commands inside a sandbox or disposable container with minimal filesystem access, no unnecessary credentials, and restricted outbound networking.
- Report detected manifests and planned operations without executing them when dependency integrity cannot be established.
