T08 · Insecure Dependencies
- Location
README.md:66- Finding
Unpinned Third-Party Package Execution via npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 66
Vulnerability Type: Supply-chain risk caused by an unpinned executable dependency
Risk Level: MediumVulnerable Code:
bash npx skills add David0Ming/skill-scaffolderTechnical Analysis
The documented installation command invokes the third-party
skillsnpm package without specifying a version or integrity constraint. If the package is not already available locally,npxmay retrieve its current published version and execute it with the installing user's privileges.Because the package version is mutable from the perspective of this project, the code executed during installation may differ from the code reviewed when this skill was audited. Compromise of the npm publisher account, package, or transitive dependency chain could therefore turn this documented installation procedure into an arbitrary-code execution channel.
This finding concerns the installation instruction rather than embedded project code. The audited project itself contains only documentation and templates; no malicious scripts were found in the project directory.
Attack Path
- An attacker compromises the npm package, its publisher account, or a transitive dependency used by the unpinned
skillspackage. - The attacker publishes a modified package version containing malicious installation or runtime behavior.
- A user follows the command documented at
README.md:66. npxresolves and downloads the attacker-controlled package version.- The package executes under the user's account during the installation workflow.
- The malicious package can perform actions permitted to that user before or while installing the skill.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user running
npx. Depending on that user's permissions and environment, an attacker could read or modify user-accessibl ...[truncated 430 chars]- An attacker compromises the npm package, its publisher account, or a transitive dependency used by the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the installer to a specific reviewed package version:
bash npx --yes skills@<reviewed-version> add David0Ming/skill-scaffolder - Verify the selected package version and its transitive dependencies before publishing the command.
- Use lockfiles and npm integrity metadata where the installation workflow supports them.
- Prefer an immutable, checksum-verified release artifact or a signed and reviewed source commit.
- Document the expected package publisher, exact version, checksum, and verification procedure.
- Recommend running installation with least privilege and without unnecessary credentials in the process environment.
- Periodically review the pinned version before upgrading rather than automatically resolving the latest release.
- Pin the installer to a specific reviewed package version:
