T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Third-Party npm Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Unpinned and mutable third-party dependency
Risk Level: MediumComplete Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"🖥️","requires":{"bins":["vibetunnel","curl","jq"]},"primaryEnv":"VT_URL","install":[{"id":"vibetunnel","kind":"node","package":"vibetunnel","bins":["vibetunnel"],"label":"Install VibeTunnel (npm)"}]}}Technical Analysis
The installation metadata specifies the npm package
vibetunnelwithout an exact version or integrity hash. Consequently, the artifact installed in the future can differ from the artifact available when this Skill was reviewed. The GitHub homepage reference does not cryptographically bind the npm package to a reviewed source revision.This creates a supply-chain risk: compromise of the package publisher, npm account, package release process, registry resolution, or a transitive dependency could introduce malicious code. Depending on the installer, malicious npm lifecycle scripts or package code could execute during installation or later when the
vibetunnelbinary is invoked.Attack Path
- An attacker compromises the npm publisher account, release pipeline, package source, or a transitive dependency used by
vibetunnel. - The attacker publishes a malicious package version under the expected package name.
- A user installs the Skill after that release is published.
- Because no exact version or integrity value is specified, the installer resolves the attacker-controlled release.
- Malicious code executes through an npm lifecycle hook or when the installed
vibetunnelexecutable is invoked. - The code operates with the privileges of the user or automation account performing the installation or execution.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the installing user's privileges. The resulting access could include re ...[truncated 303 chars]
- An attacker compromises the npm publisher account, release pipeline, package source, or a transitive dependency used by
- Remediation
View remediation
Remediation Suggestions
- Pin
vibetunnelto a reviewed exact version rather than relying on mutable registry resolution. - Use a lockfile or equivalent integrity mechanism containing registry-resolved cryptographic hashes.
- Verify npm package provenance, publisher identity, release signatures, and the correspondence between the package artifact and the referenced source repository.
- Review direct and transitive dependencies before updating the pinned version.
- Disable npm lifecycle scripts during installation where operationally possible, and explicitly review any scripts that must be enabled.
- Perform installation and execution in a least-privileged, isolated environment without unnecessary credentials or host filesystem access.
- Introduce an update process that scans and tests each proposed dependency version before changing the pin.
- Pin
