T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned npm Dependencies Download and Install Executable Binaries
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:11-13,SKILL.md:31,SKILL.md:43-48,templates/node_patterns.txt:3,templates/node_patterns.txt:80
Vulnerability Type: Unpinned third-party dependency and executable binary supply-chain risk
Risk Level: MediumVulnerable Code Snippets
SKILL.md:11-13:yaml install: - kind: npm package: ffmpeg-staticSKILL.md:31:markdown - `ffmpeg-static` downloads pre-built binaries from GitHub Releases during `npm install`. Verify the package on [npmjs.com/package/ffmpeg-static](https://www.npmjs.com/package/ffmpeg-static).SKILL.md:43-48:bash npm install ffmpeg-staticbash npm install ffmpeg-static ffprobe-statictemplates/node_patterns.txt:3:text # Requires: npm install ffmpeg-static ffprobe-statictemplates/node_patterns.txt:80:text # npm install fluent-ffmpegTechnical Analysis
The Skill declares and recommends npm dependencies without exact version constraints. In particular,
ffmpeg-staticperforms a binary download during installation, and the downloaded native executable is subsequently resolved for use by the Skill's integration patterns.Without an exact reviewed version, a committed lockfile with integrity metadata, or independent verification of the downloaded executable, installation trusts the package version currently selected by npm and the external release artifact supplied during its lifecycle. This creates a supply-chain boundary where the effective native executable may differ from the artifact originally audited.
The documentation acknowledges that
ffmpeg-staticdownloads pre-built binaries, but its recommendation to verify the package page does not cryptographically authenticate the installed package or executable. No evidence indicates that the currently referenced packages are malicious; the issue is the unsafe, mutable dependency and ...[truncated 1584 chars]- Remediation
View remediation
Remediation Suggestions
- Pin every npm dependency to an exact reviewed version rather than relying on the latest compatible release.
- Commit a lockfile containing npm integrity hashes and use
npm ciin automated installation and CI/CD environments. - Verify the downloaded FFmpeg and ffprobe binaries against trusted, version-specific SHA-256 checksums or cryptographic signatures before execution.
- Prefer disabling install-time binary downloads and provisioning FFmpeg through a separately authenticated, controlled artifact repository.
- Pin
ffmpeg-static,ffprobe-static, and optionalfluent-ffmpegversions consistently in all installation examples. - Run package installation and media processing as an unprivileged account in a sandbox or container with restricted filesystem and network access.
- Use dependency provenance, registry allowlists, package-manager audit controls, and automated monitoring for package ownership or release changes.
- Review lifecycle scripts before installation and, where operationally possible, install with scripts disabled before separately provisioning the verified executable.
