T08 · Insecure Dependencies
- Location
SKILL.md:33- Finding
Unpinned Third-Party Package Is Downloaded and Installed Automatically
- Content
View full analysis
``` ### Technical Analysis The setup downloads `truematch-plugin` from the npm registry without specifying an exact version or integrity hash. Consequently, the installed code is determined by whichever release the registry resolves at setup time rather than by the content reviewed in this project. Although `npm install` uses `--ignore-scripts`, that option only disables package lifecycle scripts during dependency installation. It does not make the downloaded plugin safe because the instructions subsequently execute `dist/index.js` directly and enable the package as a gateway plugin. The dependency's source and packaged files are absent from the audited project, so their runtime behavior cannot be verified here. The wildcard `/tmp/truematch-plugin-*.tgz` is also unsafe. If more than one matching archive exists, the command may process an unintended or attacker-planted archive. ### Attack Path 1. An attacker compromises the npm package, publisher account, registry resolution path, or one of the plugin's runtime dependencies. 2. The attacker publishes a modified release under the same package name. 3. The skill runs `npm pack truematch-plugin` without a pinned version or integrity ...[truncated 848 chars]- Remediation
View remediation
