T08 · Insecure Dependencies
- Location
SKILL.md:114- Finding
Unpinned Remote npm Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:114-127
Vulnerability Type: Unsafe third-party package retrieval and immediate execution
Risk Level: MediumVulnerable Code Snippet
bash npx likec4 validate --json --no-layout --file <edited-file> <project-dir> bunx likec4 validate --json --no-layout --file <edited-file> <project-dir> pnpm dlx likec4 validate --json --no-layout --file <edited-file> <project-dir>Related guidance:
text For evals/gradings/executions, be runner-tolerant (npx/bunx/pnpm dlx), and judge correctness by subcommand + flags + project scope. If workspace already has likec4 as a dependency, check its version from package.json and ensure it is at least 1.53.0. If pinning is needed, use the active runner (npx/bunx/pnpm dlx) with likec4@1.53.0.The same unsafe fallback pattern also appears in
references/cli.md:3-8:text Examples use bunx to run the CLI, but you should use workspace's package manager (e.g. bun, pnpm, npm). If workspace is not a npm project, use bunx (if available) -> pnpx (if available) -> npx as a fallback. If workspace already has likec4 as a dependency, check its version from package.json, make sure it is at least 1.53.0. Pin the version bunx likec4@1.53.0 ... otherwise.Technical Analysis
Package launchers such as
npx,bunx, andpnpm dlxmay resolve a package from a remote registry, download it, and immediately execute its command-line entry point. The primary examples use the unpinned package namelikec4, so the effective code can change after this Skill has been reviewed.Although the documentation mentions version
1.53.0, exact pinning is conditional rather than mandatory. It also does not require an integrity-checked lockfile, an approved registry, or prior installation of an audited local dependency. The downloaded package and its transitive dependency graph are absent from this repository and therefore were outside the ...[truncated 1631 chars]- Remediation
View remediation
Remediation Suggestions
- Add LikeC4 as an exact-version workspace dependency and commit the package-manager lockfile.
- Invoke the audited local binary rather than permitting automatic registry fallback, for example through a package script or the package manager’s local-execution mode.
- Require deterministic installation with lockfile enforcement, such as
npm ci,pnpm install --frozen-lockfile, or the equivalent for the selected package manager. - If one-shot execution is unavoidable, require an exact reviewed version such as
likec4@1.53.0; do not use an unversioned package name or@latest. - Pin and review transitive dependencies through the lockfile, and use registry integrity metadata where supported.
- Restrict package resolution to an approved registry or internal mirror.
- Run the CLI in a sandbox with minimum filesystem access, a sanitized environment, and network access disabled unless the requested operation genuinely requires it.
- Update all examples in
SKILL.mdandreferences/cli.mdso secure local, pinned execution is the default rather than optional guidance.
