T08 · Insecure Dependencies
Warning
- Location
SKILL.md:14- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 6 and 14–17
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumRelevant Code:
yaml metadata: {"clawdbot":{"emoji":"📧","requires":{"bins":["fruitmail"]},"install":[{"id":"node","kind":"node","package":"fruitmail","bins":["fruitmail"],"label":"Install fruitmail (npm)"}]}}markdown ## Installation ```bash npm install -g fruitmailtext ### Technical Analysis The skill instructs users and supporting automation to install the latest version of the third-party `fruitmail` package from the npm registry. It does not specify an exact audited version, integrity hash, lockfile, or immutable artifact reference. Because npm packages may define lifecycle scripts, package-controlled code can execute during installation with the privileges of the user running npm. The `-g` option also places the package in a global installation scope rather than isolating it to the project. The resulting CLI is then expected to access sensitive Apple Mail metadata and complete message bodies. The available file does not prove that the current `fruitmail` package is malicious. The vulnerability is the unsafe dependency trust model: a future malicious release, registry compromise, publisher-account compromise, or package replacement could cause users to install code that was not present during this audit. ### Attack Path 1. An attacker compromises the npm publisher account, registry distribution path, or another component used to publish `fruitmail`. 2. The attacker publishes a malicious release under the expected package name. 3. A user or agent follows the skill instructions and runs `npm install -g fruitmail` without an exact version or integrity constraint. 4. npm downloads the attacker-controlled release and may execute its lifecycle scripts during installation. 5. The installed global CLI executes with the invok ...[truncated 1031 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
fruitmailto an exact version in both the metadata and installation command, for examplefruitmail@X.Y.Z, after reviewing that release. - Verify the package publisher, repository, release provenance, and npm integrity digest before recommending installation.
- Use a lockfile or an immutable, integrity-verified artifact so dependency resolution cannot silently change after review.
- Audit the selected package's source, transitive dependencies, and npm lifecycle scripts.
- Disable lifecycle scripts during installation where compatible, such as with
npm install --ignore-scripts, and separately perform any required trusted setup. - Prefer a project-local or isolated installation over
npm install -gto reduce command-path exposure and simplify removal. - Run the CLI without administrative privileges and grant only the macOS permissions required to read Mail data.
- Document the package version and integrity value that were actually audited, and establish a controlled review process before updating them.
- Pin
