T08 · Insecure Dependencies
- Location
SKILL.md:334- Finding
Unpinned OpenAPI CLI Package Downloaded and Executed with npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:334-335
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code:
bash # Using npx (no install needed) npx @redocly/cli lint openapi.yamlTechnical Analysis
The Skill instructs users or agents to invoke
@redocly/clithroughnpxwithout specifying a reviewed version. If the package is not already available locally,npxcan retrieve it from the configured package registry and immediately execute its code. Because the package version and integrity are not pinned, the effective executable payload may change after the Skill has been reviewed.This creates a supply-chain trust boundary: compromise of the package publisher, registry account, transitive dependency, or package-resolution configuration could result in arbitrary code execution. OpenAPI validation requires a parser or validator, but it does not require execution of an unversioned, remotely resolved package.
Attack Path
- An attacker compromises the package, one of its dependencies, its publisher account, or the registry/resolution path.
- The attacker publishes a malicious release that can be selected by an unversioned
npxinvocation. - A user or agent follows the Skill and runs
npx @redocly/cli lint openapi.yaml. npxdownloads and executes the mutable package content.- The malicious package executes with the permissions and environment of the invoking user or agent.
Impact Assessment
Successful exploitation could execute arbitrary commands under the invoking account. Accessible scope may include project source files, writable files owned by the user, environment variables, API credentials available to the process, and network resources reachable from the host. The command does not itself request elevated operating-system privileges, so impact is generally bounded by the invoking account and its sandbox. No evidence s ...[truncated 53 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version rather than relying on the registry's current default version.
- Declare the dependency in a project manifest and commit the corresponding lockfile with integrity metadata.
- Install dependencies using a lockfile-enforcing command such as
npm ci, then invoke the locally locked binary. - Configure an approved registry and apply package provenance, signature, and integrity verification where supported.
- Require explicit user approval before downloading or executing a package that is absent locally.
- Run validation in a restricted environment with minimal filesystem access, no unnecessary credentials, and limited network access.
