T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Execution of an Unpinned npm Package Using the Mutable latest Tag
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent image-to-3D purpose, but it asks agents to run mutable remote code and globally install mutable skill content without enough pinning or validation.
Review before installing. Only use this in a sandboxed agent environment with access limited to the intended image and token, prefer pinned package versions or verified commits, and do not let the agent execute returned command strings unless you can inspect and approve the exact command.
SKILL.md:30Execution of an Unpinned npm Package Using the Mutable latest Tag
SKILL.md:42Unpinned Global Skill Installation from Mutable Third-Party Sources
SKILL.md:28Execution of a Command Dynamically Supplied by a Hosted Service
The skill instructs agents to execute an npm package via npx -y image-skill@latest, which fetches and runs the latest published code at execution time rather than a reviewed, immutable version. If the package is compromised, hijacked, or updated with malicious behavior, an agent could execute attacker-controlled code in its environment, making this a supply-chain execution risk rather than a harmless documentation issue.
The main runtime command again uses npx -y image-skill@latest, causing live retrieval and execution of whatever code is currently published under that package name. Because this command is the one intended for actual media creation and likely to be run by agents, compromise of the package could lead to arbitrary code execution, token theft, or manipulation of generated assets and billing flow.
The installation guidance uses npx skills add ... without pinning the skills package version, so the agent may execute an unreviewed package version at install time. While this is somewhat less directly dangerous than the primary runtime package if skills is well-known, it still introduces a supply-chain path for arbitrary code execution during setup.
This alternate install command also invokes npx skills without a pinned version, creating the same setup-time supply-chain risk. An attacker who can influence the published package or dependency chain could cause arbitrary code execution when an agent follows the skill's installation instructions.
No suspicious patterns detected.