T08 · Insecure Dependencies
- Location
scripts/create-token-instant.ts:53- Finding
Unpinned Runtime Dependency Execution Exposes Wallet Credentials to Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:91,SKILL.md:117, andscripts/create-token-instant.ts:53-57
Vulnerability Type: Unpinned and dynamically resolved executable dependencies
Risk Level: HighVulnerable Code
SKILL.md:91:markdown **Installation (required):** `npm install -g @four-meme/four-meme-ai@latest`. After install, run `fourmeme <command> [args]`; with local install only, use `npx fourmeme <command> [args]` from the project root.SKILL.md:117:markdown - **Invocation**: The agent must run commands only via the **fourmeme** CLI: `fourmeme <command> [args]` or `npx fourmeme <command> [args]` (allowed-tools).scripts/create-token-instant.ts:53-57:ts const child = spawnSync('npx', ['tsx', apiScript, ...args], { env: process.env, encoding: 'utf8', stdio: ['inherit', 'pipe', 'inherit'], });Technical Analysis
The documented installation command selects the mutable
latestversion of@four-meme/four-meme-airather than an audited, immutable release. The documentednpx fourmemeinvocation may also resolve or download executable npm content at runtime.In addition,
create-token-instant.tsinvokesnpx tsxand passes the complete parent environment throughenv: process.env. Write-capable operations requirePRIVATE_KEY, so a dynamically resolved or compromised executable can read that credential. The effective CLI package and its dispatcher are not included in the audited artifact, preventing their behavior and dependency integrity from being verified as part of this review.Although
npxcan use an already-installed local package, the implementation does not enforce local-only resolution, an exact version, or package integrity. Consequently, the executed code may differ from the code originally reviewed.Attack Path
- An attacker compromises the npm publisher account, a transitive dependency, the package registry ...[truncated 1547 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
@four-meme/four-meme-aiandtsxto exact audited versions rather than using@latestor unconstrainednpxresolution. - Include a lockfile with integrity hashes and install dependencies using
npm ci. - Bundle the CLI entry point and required runtime dependencies with the reviewed Skill artifact.
- Prevent network package retrieval during command execution. Prefer an explicitly resolved local executable, and fail if it is unavailable.
- Replace runtime
npx tsxexecution with compiled JavaScript or a pinned, locally installed runtime invoked by an absolute verified path. - Pass a minimal environment to child processes instead of
process.env. Include only variables strictly required by that child. - Avoid giving API-only subprocesses direct access to
PRIVATE_KEYwhere possible. Derive the wallet address and required login signature in a narrowly scoped signer component, then pass only those outputs. - Verify package provenance and signatures in CI, audit transitive dependencies, and use automated dependency-review controls.
- Run signing operations in an isolated process or hardware-backed wallet that requires explicit transaction confirmation and does not expose raw key material to npm packages.
- Pin
