T08 · Insecure Dependencies
- Location
README.md:8- Finding
Unpinned npx Package Execution Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 8
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
bash npx skills add dongsheng123132/social-copy-generatorTechnical Analysis
The documented installation command invokes
npxwithout specifying an exact version of theskillspackage. As a result, installation may resolve and execute a package release that differs from the version originally reviewed. The Skill source is also identified by a mutable GitHub owner/repository reference rather than an immutable commit hash.This creates a time-of-check/time-of-use supply-chain risk: compromise of the npm package, its maintainer account, the referenced GitHub account, or the upstream repository could alter the code ultimately executed or installed. The repository itself contains no confirmed malicious executable code; the risk arises from the mutable external dependencies used by the installation procedure.
Attack Path
- An attacker compromises the npm package, a relevant maintainer account, or the referenced GitHub repository.
- The attacker publishes a malicious
skillspackage release or replaces the repository content with a malicious Skill revision. - A user follows the documented
npx skills add dongsheng123132/social-copy-generatorinstruction. npxresolves and executes the unpinned package, which then retrieves or installs content from the mutable repository reference.- Malicious installer logic may execute with the privileges of the user running the command.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, and network resources available to that user. It could also allow modification of installed Skill content or other user-writable resources. The command does no ...[truncated 123 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI to an exact, audited package version rather than relying on the current registry release. - Pin the Skill source to an immutable Git commit hash or signed release tag.
- Use package-lock integrity data, checksums, or signature verification where supported.
- Document the expected package publisher and repository ownership so users can verify provenance before installation.
- Prefer an installation workflow that downloads and verifies artifacts before executing any installer code.
- Periodically review pinned dependencies and update them through a controlled security-review process.
- Pin the
