T08 · Insecure Dependencies
- Location
README.md:66- Finding
Unpinned npm CLI Package Is Retrieved and Executed During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 66
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable code snippet:
bash npx @skill-hub/cli install second-brain-digest --agent claudeTechnical Analysis
The installation instructions invoke
@skill-hub/clithroughnpxwithout specifying an exact package version or integrity value. Depending on npm andnpxconfiguration, this can retrieve the package version currently selected by the registry and execute its command-line entry point on the user's system.The reviewed skill therefore does not determine the exact installer code that users will execute. If the package, a maintainer account, or the package registry distribution channel is compromised after this skill is reviewed, the same documented command could retrieve and run altered code. npm lifecycle scripts and the CLI entry point may execute with the privileges of the user running the command.
No evidence was found that the current package is malicious. The vulnerability is the mutable, unpinned execution path and the resulting supply-chain exposure.
Attack Path
- An attacker compromises the
@skill-hub/clipackage, a package maintainer account, or its publication pipeline. - The attacker publishes a malicious version that is selected when the unversioned package name is resolved.
- A user follows the README and runs the documented
npxcommand. npxdownloads the attacker-controlled package version from the configured npm registry.- Package lifecycle code or the CLI entry point executes under the user's account.
- The malicious package can access resources available to that account, subject to operating-system controls and the environment in which the command was run.
Impact Assessment
Successful exploitation can result in arbitrary code execution with the privileges of the invoking user. Depending on those p ...[truncated 635 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the installer to a specific reviewed version:
bash npx --yes @skill-hub/cli@1.2.3 install second-brain-digest --agent claude -
Document the expected package provenance and publish the package's integrity digest or signed release information through a trusted channel.
-
Prefer a lockfile-backed installation workflow where feasible, and use
npm ciso the resolved dependency graph is reproducible. -
Enable npm package provenance and release signing, and instruct users to verify signatures or checksums before execution.
-
Review the pinned installer version, including its lifecycle scripts and transitive dependencies, before recommending it.
-
Run installation with a non-privileged account in an isolated environment without unnecessary credentials or sensitive environment variables.
-
Establish an update process in which the pinned version is changed only after the new release and its dependency tree have been reviewed.
-
