T08 · Insecure Dependencies
- Location
skill.md:42- Finding
Unpinned Global Installation of Third-Party npm Packages
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 42–47
Vulnerability Type: Unpinned third-party dependencies installed globally
Risk Level: MediumVulnerable Code
bash npm install -g acp-teambash npm install -g acpxTechnical Analysis
The installation instructions retrieve and execute the latest registry-resolved versions of
acp-teamandacpx. The project provides no exact versions, lockfile, integrity hashes, vendored source, or other mechanism for verifying the installed artifacts.npm installation can execute package lifecycle scripts under the installing user's account. Because
-ginstalls packages globally, their command-line executables become available system-wide for that user or installation prefix. The audited project contains onlyskill.md; consequently, the source and lifecycle behavior of these external packages could not be verified within the audit scope.This creates supply-chain exposure: a compromised publisher account, malicious release, package takeover, or unexpected upstream update could change the code executed by users after this skill has already been reviewed.
Attack Path
- An attacker compromises an upstream package, publisher account, or release process for
acp-teamoracpx. - The attacker publishes a malicious version under the package's existing name.
- A user follows the documented commands without specifying a reviewed version.
- npm resolves and downloads the mutable malicious release.
- Package lifecycle scripts may execute during installation with the installing user's privileges.
- The installed global executable can subsequently run attacker-controlled logic whenever the documented workflow invokes it.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user performing the installation. Potential effects include reading or modifying user-accessible files, accessing environment variables and credentia ...[truncated 516 chars]
- An attacker compromises an upstream package, publisher account, or release process for
- Remediation
View remediation
Remediation Suggestions
-
Pin both dependencies to exact, reviewed versions rather than resolving the latest release:
bash npm install --save-exact acp-team@<reviewed-version> acpx@<reviewed-version> -
Prefer project-local installation and invoke the binaries through
npm execor package scripts instead of installing them globally. -
Commit a lockfile generated from reviewed artifacts and enforce lockfile-based installation with
npm ci. -
Verify package provenance, publisher identity, registry source, and integrity metadata before installation.
-
Audit the packages' source, transitive dependencies, binaries, and lifecycle scripts for each approved release.
-
Where compatible with the packages, use
--ignore-scriptsduring installation and explicitly run only reviewed setup operations. -
Run the tools under a dedicated, least-privileged account or sandbox without unnecessary access to credentials, sensitive files, or administrative resources.
-
Establish an update-review process so version changes and lockfile modifications require security review before deployment.
-
