T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned Executable npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–16
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
yaml install: - kind: node package: "@baomihuatop/popcorn-cli" bins: - popcorn-cliTechnical Analysis
The Skill installs an executable third-party npm package without specifying an exact version, lockfile, or integrity hash. Consequently, the code installed during a future deployment can differ from the package version assessed when this Skill was reviewed.
Because the dependency provides the
popcorn-cliexecutable, its code runs under the identity and permissions of the Agent user. Package installation may also execute npm lifecycle scripts, depending on the installer configuration. The dependency implementation is not included in this repository, so its runtime behavior, transitive dependencies, and handling of API credentials cannot be independently verified from the audited files.This is a supply-chain weakness rather than evidence that the currently published package is malicious.
Attack Path
- An attacker compromises the npm publisher account, package release process, or a transitive dependency.
- The attacker publishes a malicious release under the existing package name.
- A subsequent Skill installation resolves the unpinned package to the malicious release.
- Malicious code executes during installation or when
popcorn-cliis invoked. - The code accesses data available to the Agent process, potentially including the Popcorn API key, submitted prompts, generated media, task identifiers, and other user-readable files.
Impact Assessment
Exploitation could result in arbitrary code execution with the privileges of the user installing or invoking the Skill. The practical scope includes files, environment variables, network credentials, and services accessible to that account. The finding does not ind ...[truncated 157 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@baomihuatop/popcorn-clito an exact, reviewed version rather than resolving an unspecified release. - Provide a lockfile and verify the package with a trusted registry integrity hash.
- Disable npm lifecycle scripts during installation unless they are explicitly required and audited.
- Audit the package and all transitive dependencies with software-composition analysis and malware scanning.
- Publish verifiable source code corresponding to each distributed package release.
- Run the CLI with least privilege in a sandbox that restricts filesystem, environment-variable, and network access.
- Establish a controlled update process that reviews and approves new versions before deployment.
- Pin
