T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Remote npm Package Installation and Execution
- Content
View full analysis
" --pretty --source-client socialdatax-skills \ --source-platform clawhub --source-skill socialdatax-kuaishou-detail npx -y socialdatax-skills@latest kuaishou detail \ --url "" --pretty \ --source-client socialdatax-skills --source-platform clawhub \ --source-skill socialdatax-kuaishou-detail ``` ```text When the user wants to save Kuaishou media after detail, pass each returned `images[].url`, `video.play_url`, or `cover_image_url` to `npx -y socialdatax-skills@latest kuaishou download-media --url "" --output-dir --pretty`; this local save command does not require `SOCIALDATAX_API_KEY`. ``` ```text If the current environment has permission, install or restore automatically. ``` ### Technical Analysis The Skill directs the agent to fetch and execute `socialdatax-skills@latest` through `npx -y`. The `@latest` selector is mutable, so the code executed at runtime may differ from the code available when the Skill was audited. No exact version, package-lock entry, or integrity hash constrains the retrieved package. The `-y` option also suppresses the normal installation confirmation. The installation metadata similarly identifies `socialdatax-skills` without an exact version. The troubleshooting instructions encourage automatic dependency installation or restoration when permission is available, increasing the likelihood that unreviewed ...[truncated 2123 chars]- Remediation
View remediation
