T08 · Insecure Dependencies
- Location
SKILL.md:378- Finding
Execution of an Unpinned Registry Package Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 378
Vulnerability Type: Unpinned third-party package execution
Risk Level: HighVulnerable Code Snippet:
bash # Install the skill npx molthub@latest install skill-nameTechnical Analysis
The documented workflow uses
npxto retrieve and execute the mutablelatestrelease of themolthubpackage. No exact version, integrity hash, lockfile, provenance check, or trusted package-source validation is required.Because the
latesttag can be reassigned after this skill has been reviewed, the code ultimately executed may differ from the code that was originally assessed. Package installation hooks and the package executable run with the permissions of the user invokingnpx.This is a supply-chain weakness. Exploitation would require compromise of the package, its publisher account, the registry distribution process, or another mechanism capable of causing an unsafe release to resolve through the specified package name.
Attack Path
- An attacker compromises the package publisher, registry entry, or release pipeline for
molthub. - The attacker publishes a malicious release and assigns it to the
latestdistribution tag. - A reviewer follows the documented workflow and runs
npx molthub@latest install skill-name. npxdownloads and executes the attacker-controlled release.- The malicious package executes with the invoking user's permissions and can access resources available to that account.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the privileges of the user running the review workflow. The accessible scope may include project files, user-owned files, environment variables, developer credentials, package-manager credentials, and network resources available to that account.
This instruction does not itself request elevated privileges, so direct root or administrator ...[truncated 146 chars]
- An attacker compromises the package publisher, registry entry, or release pipeline for
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable
latesttag with an explicitly audited package version, such asmolthub@X.Y.Z. - Verify package ownership, source repository, release provenance, and signatures before execution.
- Use lockfiles and registry-supported integrity metadata where applicable.
- Configure the package manager to use a trusted registry rather than an uncontrolled mirror.
- Review package lifecycle scripts before allowing installation or execution.
- Run the installation in a disposable, non-root sandbox without secrets or host filesystem mounts.
- Disable outbound networking during execution unless network access is essential.
- Document the expected package checksum or other verifiable release identity and provide a process for securely updating it.
- Replace the mutable
