T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 30
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code:
bash npx lighthouse https://your-site.com --output html --output-path ./report.htmlTechnical Analysis
The documented command invokes
lighthousethroughnpxwithout specifying an approved package version. If the package is not already available locally,npxmay retrieve and execute a mutable release from the configured package registry. The command also provides no lockfile or integrity verification.Consequently, the code executed when users follow this instruction can differ from the code originally reviewed. Exploitation would require compromise of the upstream package, registry, dependency chain, or package-resolution environment. No evidence in the audited files indicates that the skill author controls such a payload or intentionally introduced a malicious package.
Attack Path
- A user follows the command documented in
SKILL.md. npxresolveslighthousethrough the user's configured package registry.- If it is unavailable locally,
npxdownloads the currently resolved package and its dependencies. - A compromised or unexpectedly changed package executes during installation or invocation.
- The package runs with the permissions and environment access of the user who launched
npx.
Impact Assessment
A compromised dependency could execute arbitrary code with the invoking user's privileges. Depending on the user's environment, this could expose readable project files, environment variables, local credentials, and network-accessible resources, or modify files writable by that user. The audited project itself contains no embedded executable scripts, persistence mechanism, privilege-escalation logic, credential access, or data-exfiltration behavior.
- A user follows the command documented in
- Remediation
View remediation
Remediation Suggestions
-
Pin Lighthouse to a specifically reviewed version, for example:
bash npx --yes lighthouse@12.8.2 https://your-site.com --output html --output-path ./report.html -
Regularly review and deliberately update the pinned version rather than resolving an unspecified release.
-
For reproducible organizational workflows, declare Lighthouse in a development manifest, commit the lockfile, use deterministic installation such as
npm ci, and invoke the locally installed binary. -
Apply registry allowlisting, lockfile integrity validation, and dependency scanning where the command is used in sensitive environments.
-
Prefer the built-in Chrome DevTools Lighthouse workflow when local third-party package execution is unnecessary.
-
