T08 · Insecure Dependencies
- Location
README.md:33- Finding
Unpinned NPX Installer Executes Mutable Third-Party Code
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 33-36
Vulnerability Type: Unpinned third-party installer and mutable skill source
Risk Level: MediumComplete Code Snippet:
bash **Option 2: Install via NPX (For other coding agents)** ```bash npx skills add hqman/qveristext ### Technical Analysis The documented installation command invokes the `skills` package through `npx` without specifying an exact package version or integrity hash. If the package is not already installed locally, `npx` may retrieve and execute its current published version. Consequently, the code executed during installation can differ from the code that was reviewed. The `hqman/qveris` skill reference is also not pinned to an immutable release or commit hash. This creates a second mutable supply-chain boundary: even if the installer remains trustworthy, it may retrieve a later or compromised revision of the referenced skill. This behavior is not required by the core runtime functionality. The audited runtime script uses only Node.js built-in APIs and can be installed manually. The unpinned NPX method therefore introduces additional installation-time privileges and supply-chain exposure beyond the minimum needed to run the skill. ### Attack Path 1. An attacker compromises the npm account, publication process, or repository associated with the `skills` package, or causes a malicious version to be resolved. 2. Alternatively, the attacker compromises or maliciously modifies the mutable `hqman/qveris` source referenced by the command. 3. A user follows the installation instructions and runs `npx skills add hqman/qveris`. 4. `npx` retrieves the currently resolved installer package, which can execute code under the user's account. 5. The installer retrieves or installs the mutable skill source. 6. Malicious installer or skill code can then act with the permissions available to the invoking process. ### Impact Asses ...[truncated 778 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the NPX package to a reviewed exact version, for example by using an explicit version rather than the latest resolved release.
- Pin the skill source to an immutable commit hash or cryptographically verified release instead of the mutable
hqman/qverisreference. - Publish and verify integrity information, such as expected package hashes, signed release artifacts, or npm provenance.
- Document the expected npm publisher, source repository, exact reviewed version, and verification procedure.
- Use
npxoptions that prevent unexpected interactive package installation where supported, and fail closed if the pinned package is unavailable. - Prefer the documented manual installation of reviewed local artifacts for security-sensitive environments.
- Advise users not to run the installer with elevated privileges and to use an isolated environment containing no unrelated credentials.
