T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Third-Party npm Package Executed Without Artifact Integrity Verification
- Content
View full analysis
``` ```bash npm install -g @dlazy/cli@1.0.9 ``` ### Technical Analysis The Skill directs the agent to install or immediately execute the externally hosted npm package `@dlazy/cli@1.0.9`. Pinning the package version reduces uncontrolled version drift, but it does not verify the integrity or provenance of the downloaded artifact. No package digest, trusted lockfile, vendored implementation, signature verification, or reproducible-build verification is provided in the audited project. The linked GitHub repository improves transparency but does not establish that the npm artifact is identical to the reviewed repository source. In addition, npm installation may execute package lifecycle scripts and load transitive dependencies. Consequently, the effective executable payload is outside the two audited documentation files. No evidence establishes that the current package is malicious. The confirmed issue is the trust boundary created by executing an external package without cryptographic artifact verification. ### Attack Path 1. An attacker compromises the npm publisher account, the package release process, or a transitive dependency used by ...[truncated 1441 chars]- Remediation
View remediation
