T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned npm CLI Execution and Unsafe Sourcing of Generated Configuration
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 12–19
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
bash # Check if authenticated echo $ATXP_CONNECTION # If not set, login: npx atxp login source ~/.atxp/configTechnical Analysis
The skill instructs the agent to execute
npx atxpwithout specifying an exact package version, lockfile, package integrity hash, or trusted installation artifact. Consequently, the package resolved by npm at execution time can differ from the package that existed when the skill was audited.This creates a mutable supply-chain boundary. If the package, one of its transitive dependencies, the registry account, or the package-resolution environment is compromised, running
npx atxp logincan execute attacker-controlled JavaScript with the privileges of the agent process.The subsequent
source ~/.atxp/configcommand executes the generated file as shell code in the current shell rather than treating it as passive configuration data. If the CLI or generated file is compromised, arbitrary commands embedded in that file will run and may also alter the current process environment.No evidence establishes that the current
atxppackage is malicious. The issue is the absence of controls ensuring that the reviewed dependency is the dependency executed later.Attack Path
- An attacker compromises the
atxpnpm package, a transitive dependency, or an account authorized to publish it. - The attacker publishes a modified package version containing a malicious installation hook or runtime payload.
- An agent follows the skill and executes
npx atxp loginwithout an exact version or integrity constraint. - npm resolves and runs the attacker-controlled package.
- The package reads accessible environment variables and files, including the ATXP connection credential, or writes malicious shell commands to
~/.atxp/config. - The agent executes ...[truncated 790 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an audited exact version, for example
npx --yes atxp@X.Y.Z, rather than resolving an unconstrained package version. - Install dependencies through a committed lockfile and use a reproducible command such as
npm ci. - Verify package provenance and integrity through registry signatures, checksums, or a trusted internal package mirror.
- Review and constrain transitive dependencies and enable automated dependency monitoring.
- Run the CLI in a sandbox with only the filesystem, network, and environment access required for the requested operation.
- Do not source a file generated by a third-party executable. Parse the required value as data, validate its format, and export it explicitly.
- Restrict permissions on credential files, and avoid exposing unrelated secrets to the CLI process.
- Document the expected official package registry and publisher identity to reduce dependency-confusion and package-substitution risk.
- Pin the CLI to an audited exact version, for example
