T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25–29
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Mediummarkdown 若 `mddoc` 未安装: ```bash npm install -g mddoc-clitext ### Technical Analysis The skill directs the agent to install `mddoc-cli` from the npm registry without specifying a reviewed version, lockfile, or integrity hash. Consequently, the package content installed at execution time can differ from the content that was available when the skill was audited. npm installation can execute package lifecycle scripts with the permissions of the account running the agent. The `-g` option also places the package in the configured global npm prefix rather than isolating it within the current project. If the package, one of its transitive dependencies, or its publishing account is compromised, installation could execute attacker-controlled code and modify globally available user tooling. ### Attack Path 1. A user invokes the skill to generate a diagram. 2. The dependency check determines that the `mddoc` executable is unavailable. 3. The agent follows the skill instructions and executes `npm install -g mddoc-cli`. 4. npm resolves the current package release and its transitive dependencies from the registry without an audit-pinned version or integrity policy. 5. A compromised or malicious package version executes an npm lifecycle script during installation. 6. The script operates with the invoking account's privileges and can access that account's files, environment variables, network connectivity, and writable npm global prefix. ### Impact Assessment Successful exploitation could provide arbitrary code execution with the privileges of the account running the installation. An attacker could read or modify files accessible to that account, access exposed environment variables, communicate over the network, and replace or modify executables in the writa ...[truncated 349 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
mddoc-clito a specific reviewed version rather than installing the latest release implicitly. - Prefer a project-local dependency recorded in
package.jsonand a committed lockfile instead of global installation. - Use a reproducible installation command such as
npm ciwith lockfile integrity metadata. - Verify the package publisher, provenance, signatures where available, and expected integrity before installation.
- Review the package and its transitive dependencies, including npm lifecycle scripts.
- Disable lifecycle scripts during installation when they are unnecessary, for example with
--ignore-scripts, after confirming that this does not prevent legitimate operation. - Require explicit user approval before downloading or installing external software.
- Execute diagram tooling in a sandbox or container with minimal filesystem access, no unnecessary credentials, and restricted network access.
- Document an approved installation procedure separately instead of automatically directing the agent to modify global tooling.
- Pin
