T08 · Insecure Dependencies
- Location
SKILL.md:76- Finding
Unpinned npm Package Is Downloaded and Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15 and 76–82
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
At line 15:
yaml Optional: validate DESIGN.md with `npx @google/design.md lint DESIGN.md` (requires Node.js).At lines 76–82:
bash npx @google/design.md lint DESIGN.mdYou can also export the tokens to Tailwind or W3C DTCG format:
bash npx @google/design.md export --format css-tailwind DESIGN.md > theme.cssTechnical Analysis
The documented commands invoke
@google/design.mdthroughnpxwithout specifying an exact package version or verifying an integrity hash. If the package is not already available locally,npxcan resolve and download a mutable version from the configured npm registry before executing its binary.Consequently, the code executed by these commands can change after the Skill has been audited. A compromised package release, maintainer account, transitive dependency, or registry response could introduce malicious code. Depending on npm configuration and the package contents, installation lifecycle scripts may also execute during package acquisition.
Although these commands are described as optional, users following the documented validation or export procedure are exposed to this supply-chain risk. The export command also redirects output to
theme.css, which overwrites that file if it already exists.Attack Path
- An attacker compromises the npm package, a maintainer account, a transitive dependency, or the package-resolution infrastructure.
- The attacker publishes or serves a malicious version under the expected
@google/design.mdpackage name. - A user follows the Skill documentation and runs one of the unversioned
npxcommands. npxresolves and downloads the mutable package version from the configured registry.- Malicious package installation logic or the package executable runs with the privileges of ...[truncated 776 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed, exact version rather than allowing
npxto resolve the latest release:bash npx --yes @google/design.md@EXACT_REVIEWED_VERSION lint DESIGN.md npx --yes @google/design.md@EXACT_REVIEWED_VERSION export --format css-tailwind DESIGN.md > theme.css -
Prefer declaring the package in a development dependency manifest and committing a lockfile containing integrity metadata. Invoke the lockfile-resolved local binary through a package script.
-
Review the selected package version and its transitive dependency tree before use. Update it through a controlled dependency-review process.
-
Disable lifecycle scripts during installation where compatible with the package:
bash npm install --ignore-scripts -
Execute optional tooling in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited outbound network connectivity.
-
Clearly disclose that the validation and export procedures download and execute third-party code and are not purely documentation-only operations.
-
Avoid accidental output-file replacement by checking whether
theme.cssexists or writing to a temporary file before performing an explicit atomic replacement.
-
