T08 · Insecure Dependencies
- Location
package.json:13- Finding
Mutable Third-Party Dependencies Installed Without a Lockfile
- Content
View full analysis
Vulnerability Details
File Location:
package.json:13-18andREADME.md:34-37
Vulnerability Type: Supply-chain exposure through mutable dependency versions
Risk Level: MediumThe project instructs users to install dependencies while specifying all direct dependencies with mutable caret version ranges. No lockfile, integrity hashes, vendored dependency sources, or other reproducible-installation controls were included in the audited artifact.
Relevant installation instruction (
README.md:34-37):bash # Install dependencies pnpm installComplete dependency declaration (
package.json:13-18):json "dependencies": { "@bondli-skills/shared": "^1.0.0", "axios": "^1.6.0", "puppeteer": "^22.0.0", "puppeteer-core": "^22.15.0" }Technical Analysis
Caret ranges permit the package manager to resolve newer compatible releases than those originally reviewed. Because the repository contains no lockfile, separate installations can resolve to different package versions and transitive dependency trees.
Package installation can also invoke dependency lifecycle scripts. If an allowed dependency version or one of its transitive dependencies is compromised, a malicious release can execute code during installation or introduce malicious runtime behavior. The scoped package
@bondli-skills/sharedcould not be audited from the supplied artifact, and its provenance and effective installed contents are therefore unknown.This risk is particularly relevant because the documented skill is intended to interact with an existing authenticated Chrome session for a corporate GitLab instance. A malicious dependency running in that context could attempt to access local files, environment variables, browser debugging interfaces, or authenticated browser data available to the process.
Attack Path
- An attacker compromises a declared dependency, its publisher account, or a transitive d ...[truncated 1237 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace caret ranges with reviewed, exact dependency versions.
- Generate and commit
pnpm-lock.yamlso direct and transitive dependency resolution is reproducible and includes package integrity information. - Review the ownership, publication history, source, and packaged contents of
@bondli-skills/sharedbefore trusting it in a process that can access an authenticated browser session. - Use continuous dependency scanning and monitor dependencies for compromised releases and known vulnerabilities.
- In automated or high-trust environments, install with the frozen-lockfile option so dependency drift causes installation to fail.
- Disable dependency lifecycle scripts where operationally feasible, or explicitly review every package that requires such scripts before permitting execution.
- Run installation and collection under a dedicated, least-privileged account with restricted filesystem and network access.
- Avoid exposing the browser debugging interface beyond the local machine, and ensure the process can connect only to the intended browser session and GitLab host.
