T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned and Unverified npm Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Third-party software supply-chain risk
Risk Level: MediumVulnerable Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"🌐","requires":{"bins":["trans"],"env":["TRANS_API_KEY"]},"install":[{"id":"npm","kind":"npm","package":"@bdtrans/trans-cli","bins":["trans"],"label":"Install trans-cli (npm)"}]}}Technical Analysis
The skill declares automatic installation of the external npm package
@bdtrans/trans-cliwithout specifying an exact audited version, lockfile, registry restriction, or integrity hash. Consequently, future installations may resolve to package contents that differ from those present when the skill was reviewed.The external package's implementation is not included in this project, so its installation scripts and runtime behavior could not be examined. The declared executable handles translation text and requires access to
TRANS_API_KEY. If the npm package, its publisher account, or its dependency chain were compromised, malicious lifecycle or runtime code could execute in the installing user's environment.This is a supply-chain exposure rather than proof that the named package is currently malicious. Exploitation depends on compromise, replacement, or unsafe resolution of the external dependency.
Attack Path
- An attacker compromises the npm publisher account, package, dependency chain, or relevant package-resolution infrastructure.
- The attacker publishes a malicious package version or causes installation to resolve to attacker-controlled content.
- The skill installer processes the unversioned
@bdtrans/trans-clideclaration and retrieves the affected version. - Malicious code executes through an npm lifecycle script or when the
transbinary is invoked. - The code accesses data available to the process, potentially including
TRANS_API_KEY, submitted translation text, configuration fi ...[truncated 693 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@bdtrans/trans-clito a specific, reviewed version rather than allowing mutable package resolution. - Maintain and verify a lockfile containing registry-resolved integrity hashes.
- Restrict installation to the authoritative npm registry and document the trusted package publisher and source repository.
- Review the package, its transitive dependencies, and its npm lifecycle scripts before approving upgrades.
- Disable npm lifecycle scripts during installation where the package does not require them, and execute the CLI in a least-privileged environment.
- Provide only the required API credential to the translation process and avoid exposing unrelated secrets through its environment.
- Consider vendoring or otherwise reproducibly packaging the reviewed executable so that installed code matches the audited artifact.
- Establish dependency monitoring and a controlled update process for publisher compromise, malicious releases, and newly disclosed vulnerabilities.
- Pin
