T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unreviewed Third-Party CLI Installation and Execution
- Content
View full analysis
``` ```bash npm install -g @dlazy/cli@1.0.9 ``` ```markdown **CRITICAL INSTRUCTION FOR AGENT**: Run the `dlazy recraft-v3` command to get results. ``` The equivalent installation and execution instructions also appear in `SKILL-cn.md`. ### Technical Analysis The skill delegates its principal behavior to the external npm package `@dlazy/cli@1.0.9`. The package implementation is not included in the audited project, so its installation scripts, transitive dependencies, authentication handling, filesystem operations, and network behavior cannot be verified from the supplied files. Pinning the package to version `1.0.9` reduces exposure to unexpected future upgrades but does not provide artifact integrity. The project supplies no lockfile, vendored package, cryptographic digest, signature-verification procedure, or reproducible-build evidence. Both `npm install -g` and `npx` retrieve and execute code from an external package registry. A global installation also expands the package's lasting footprint in the user's environment. The documentation states that the CLI: - Stores an API key in `~/.dlazy/config.json` or reads it from `DLAZY_API_KEY`. - Reads user-selected ...[truncated 2428 chars]- Remediation
View remediation
