T08 · Insecure Dependencies
- Location
SKILL.md:43- Finding
Unpinned npx Invocation May Execute an Untrusted Registry Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:43
Vulnerability Type: Insecure dependency resolution and implicit package execution
Risk Level: MediumVulnerable Code Snippet:
markdown - Node/TS: - 必跑:`npm run lint`、`npx tsc --noEmit`Technical Analysis
The skill instructs the agent to execute
npx tsc --noEmit. If the reviewed repository does not provide a localtscexecutable,npxmay resolve and download a package from the configured npm registry. The command identifies the executable by the ambiguous package nametscinstead of requiring a lockfile-pinned installation of the officialtypescriptpackage.This creates a supply-chain risk because execution can depend on mutable registry content rather than dependencies already reviewed and installed from the repository lockfile. Package lifecycle scripts or the resolved executable can run arbitrary code with the privileges of the user operating the agent.
Attack Path
- An attacker prepares or influences a Node.js repository that lacks a local, lockfile-pinned TypeScript compiler.
- The user invokes this code-review skill against that repository.
- Following
SKILL.md, the agent runsnpx tsc --noEmit. - Because no trusted local
tscexecutable is available,npxresolves the package through the configured npm registry and may download it. - Registry-supplied package code or lifecycle scripts execute on the audit host under the agent user's account.
- The package can access files, environment variables, network resources, and credentials available to that account.
Exploitation depends on the local npm/npx version and configuration permitting package downloads, and on the absence of a trusted local executable.
Impact Assessment
Successful exploitation permits arbitrary code execution with the privileges of the user running the skill. The affected scope can include the reviewed repository, other files wr ...[truncated 275 chars]
- Remediation
View remediation
Remediation Suggestions
-
Require
typescriptto be declared in the repository's development dependencies and pinned through a committed lockfile. -
Prohibit implicit package downloads during review.
-
Invoke only the installed local executable, for example:
bash ./node_modules/.bin/tsc --noEmitAlternatively, use an npm execution mode configured to reject installation when the executable is absent, such as:
bash npm exec --offline --no -- tsc --noEmit -
Before execution, verify that the resolved binary belongs to the installed, expected
typescriptpackage. -
If the trusted local compiler is unavailable, record the type check as not executed instead of retrieving a package dynamically.
-
Run repository-controlled validation commands in an isolated, least-privileged environment without production credentials.
-
