T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party Installer and Mutable Skill Source
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 7
Vulnerability Type: Supply-chain risk from an unpinned installer and mutable repository source
Risk Level: MediumVulnerable Command:
shell npx skills add Eric-Yibo-Shen/zhangxuefeng-skillsetTechnical Analysis
The installation command uses
npxwithout pinning theskillspackage to an audited version. Depending on the local package state and npm behavior,npxcan retrieve and execute the currently published package version. The referenced Skill source is also identified by a repository path rather than an immutable commit hash or verified release artifact.This creates a time-of-check/time-of-use supply-chain risk: the code and Skill content executed during a future installation may differ from the content reviewed during this audit. An attacker who compromises the npm package, publisher account, repository, or maintainer credentials could replace the installer or repository content with a malicious version.
No evidence was found that the currently audited project contains malicious executable code. The risk concerns the mutable external components used by the documented installation procedure.
Attack Path
- An attacker compromises the npm publisher account for the invoked installer package, its distribution channel, or the referenced repository.
- The attacker publishes a modified installer version or changes the repository content.
- A user follows the documented command.
npxretrieves and executes the unpinned installer package.- The installer retrieves the mutable Skill source rather than a verified immutable revision.
- Malicious package lifecycle code, installer logic, or installed Skill content executes or becomes available under the user's account.
Impact Assessment
A malicious npm installer can potentially execute code with the privileges of the user running
npx. This may permit access to file ...[truncated 401 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm package to an exact, audited version rather than allowingnpxto resolve the current release. - Reference the Skill repository by an immutable commit hash or a signed release tag.
- Publish and verify a cryptographic checksum for the expected installation artifact.
- Use npm lockfiles and integrity metadata where the installation workflow supports them.
- Disable or review package lifecycle scripts before installation.
- Run installation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network permissions.
- Document the expected installer version, repository commit, checksum, and verification procedure directly beside the installation command.
- Re-audit dependencies and installed content whenever the pinned versions are updated.
- Pin the
