T08 · Insecure Dependencies
- Location
README.md:47- Finding
Unpinned Third-Party Installer and Mutable Skill Source
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 47
Vulnerability Type: Supply-chain exposure through unpinned third-party code
Risk Level: MediumVulnerable Code
bash npx skills add Flacko2048/million-dollar-landingTechnical Analysis
The documented installation command invokes the
skillspackage throughnpxwithout specifying an audited package version. It also identifies the Skill through a mutable GitHub owner/repository reference rather than an immutable commit SHA or signed release.Consequently, the command may resolve different installer code or Skill content over time. The local files reviewed in this audit therefore do not necessarily represent the files that a user will receive when running the command later. If the npm package, npm publisher account, GitHub account, or referenced repository is compromised, an attacker could distribute altered instructions or executable content through the legitimate-looking installation command.
This is a supply-chain weakness rather than evidence that the currently reviewed React components contain malicious code.
Attack Path
- An attacker compromises the npm package, its publisher account, the referenced GitHub account, or the repository.
- The attacker publishes a malicious installer version or modifies the repository's current revision.
- A user follows the README and runs the unpinned
npx skills add Flacko2048/million-dollar-landingcommand. npxresolves and executes the mutable third-party installer, which retrieves or installs the current mutable Skill content.- Installer-level malicious code may execute immediately with the invoking user's privileges. Alternatively, malicious Skill instructions or files may become active when the installed Skill is subsequently loaded or used.
Impact Assessment
Installer-level compromise could execute code with the privileges of the user running
npx, potentially allow ...[truncated 744 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsinstaller to a specific audited version:bash npx skills@<audited-version> add ... - Pin the Skill source to an immutable commit SHA or a cryptographically signed release instead of relying on the repository's current default branch.
- Publish SHA-256 checksums or signed provenance for released Skill archives and verify them before installation.
- Prefer downloading and reviewing the Skill locally before installing it, particularly in environments containing source-control, cloud, package-registry, or deployment credentials.
- Run installation with least privilege in an isolated environment. Do not use
sudo, and avoid exposing unrelated secrets through environment variables. - Document the exact installer version and Skill commit that correspond to the audited release.
- Pin the
