T08 · Insecure Dependencies
- Location
SKILL.md:39- Finding
Unaudited Third-Party CLI Is Installed Globally and Entrusted with Sensitive Data
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 39–43 and 100–105
Vulnerability Type: Supply-chain exposure through a globally installed third-party executable
Risk Level: MediumVulnerable Code
bash if ! command -v coil >/dev/null 2>&1; then npm install --global @usecoil/cli@0.1.4 fi coil --versionThe installation is repeated in the runtime setup:
bash npm install --global @usecoil/cli@0.1.4 coil config set-base-url https://www.usecoil.com --profile prod printf '%s' "$COIL_API_KEY" | coil auth login --profile prod --key - coil --profile prod agent-context --jsonTechnical Analysis
The Skill instructs the agent to download and globally install
@usecoil/cli@0.1.4from npm, then supplies the resulting executable with an organization API key and uses it for provider integrations, LinkedIn-backed scraping, lead management, and outbound automation.Pinning an exact version reduces exposure to unexpected upgrades, but the project does not include the dependency's source, an integrity hash, a lockfile, a cryptographic signature, or another mechanism by which the downloaded artifact can be verified against audited code. Its effective behavior is therefore outside the reviewed project.
A global npm installation may execute package lifecycle scripts and places an executable into a shared command path. If the npm publication, maintainer account, registry delivery path, or referenced package version is compromised, attacker-controlled code could execute with the installing user's privileges. The installed CLI would also be in a position to read secrets deliberately passed over stdin and all business data processed through later commands.
Attack Path
- An attacker compromises the npm package publication process, its maintainer account, registry infrastructure, or the artifact associated with
@usecoil/cli@0.1.4. - The user or agent follows the Skill and runs the ...[truncated 1584 chars]
- An attacker compromises the npm package publication process, its maintainer account, registry infrastructure, or the artifact associated with
- Remediation
View remediation
Remediation Suggestions
- Publish auditable source corresponding exactly to the supported CLI release.
- Distribute signed release artifacts and verify their cryptographic signatures or documented SHA-256 hashes before execution.
- Avoid global installation. Prefer a project-local, locked dependency or a verified standalone binary in a dedicated directory.
- Disable npm lifecycle scripts where feasible, such as with
--ignore-scripts, after confirming that the package does not legitimately require them. - Use a lockfile and registry integrity metadata when installing through npm.
- Run the CLI in a sandbox with restricted filesystem access, a minimal environment, and network access limited to approved Coil and provider endpoints.
- Continue passing secrets through stdin or a runtime secret manager rather than command-line arguments.
- Use narrowly scoped, short-lived credentials where supported, and rotate them after suspected dependency compromise.
- Document the expected package publisher, checksum, signing identity, and authorized network destinations so installations can fail closed on mismatch.
