T08 · Insecure Dependencies
- Location
references/audit-script-engineering.sh:266- Finding
Unpinned npx Execution May Retrieve and Run an Untrusted Package
- Content
View full analysis
Vulnerability Details
File Location:
references/audit-script-engineering.sh, lines 266-267
Vulnerability Type: Supply-chain risk from implicit remote package resolution and execution
Risk Level: MediumVulnerable Code
bash if command -v npx &>/dev/null && [ -f "tsconfig.json" ]; then TS_ERRORS=$(npx tsc --noEmit 2>&1 | grep -c "error TS" || echo "0")Technical Analysis
The audit script invokes
npx tscwithout requiring a lockfile-installed local TypeScript compiler, preventing package installation, pinning a version, or enforcing offline resolution.Depending on the installed npm/npx version and project state, if the expected executable is unavailable locally,
npxmay resolve and download a package from the configured package registry and execute its binary. This allows the effective code run by the audited Skill to differ from the code reviewed in the Skill package.The command is especially sensitive because the script is intended to run inside arbitrary software repositories. Any remotely resolved package executes with the invoking user's permissions and can access files and environment variables available to the audit process. Local TypeScript compilation is legitimate for the declared consistency-checking function, but allowing implicit network retrieval is not the minimum privilege necessary to perform it.
No direct secret transmission command was found. The script's
fetch(...)pattern is only a source-code search, and its secret checks print findings locally. The security concern is the conditional supply-chain execution channel created bynpx.Attack Path
- A user runs the mandated audit script against a project containing
tsconfig.json. npxis available, satisfying the condition on line 266.- The intended TypeScript compiler executable is absent from the project's installed dependencies, or package resolution is influenced by an unsafe registry configuration.
- `n ...[truncated 1040 chars]
- A user runs the mandated audit script against a project containing
- Remediation
View remediation
Remediation Suggestions
- Require TypeScript to be installed as a pinned development dependency and committed to the project's lockfile.
- Invoke the verified local binary directly:
bash if [ -x "./node_modules/.bin/tsc" ] && [ -f "tsconfig.json" ]; then TS_ERRORS=$(./node_modules/.bin/tsc --noEmit 2>&1 | grep -c "error TS" || echo "0") else log_warn "Pinned local TypeScript compiler unavailable — skipping compilation check" fi- If
npxmust be retained, prohibit installation and require local resolution using an option supported by the project's pinned npm version, such as:
bash npx --no-install tsc --noEmit- Alternatively, use an explicitly offline package-execution mode and treat resolution failure as a skipped check or controlled blocker rather than permitting a download.
- Verify lockfile integrity in CI and use an approved registry with dependency allowlisting and package-integrity checks.
- Run the audit in a sandbox with network access disabled, minimal environment variables, read-only repository access where practical, and no production credentials.
- Document that the audit script performs no dependency installation and must not retrieve executable code during an audit.
