T08 · Insecure Dependencies
- Location
package.json:36- Finding
Unpinned Third-Party Package Execution and Dependency Resolution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:369,README.md:48, andpackage.json:36-45
Vulnerability Type: Supply-chain exposure through unpinned package execution and dependency resolution
Risk Level: MediumComplete Code Snippets
SKILL.md:369andREADME.md:48:bash npx skills add <owner/repo>@decision-expertpackage.json:36-45:json "dependencies": { "commander": "^11.0.0", "inquirer": "^9.2.0", "chalk": "^5.3.0", "cli-table3": "^0.6.3", "lodash": "^4.17.21", "yaml": "^2.3.0", "json2csv": "^6.0.0", "markdown-table": "^3.0.3" },Technical Analysis
The installation instructions invoke the unversioned
skillspackage throughnpx. When the package is not already available locally,npxmay resolve, download, and execute the package currently published under that registry name. The artifact does not pin the executable package to a reviewed version, and the placeholder<owner/repo>does not identify a concrete, verifiable source revision.Runtime dependencies use caret version ranges, allowing npm to resolve newer compatible releases than those originally reviewed. The audited directory structure contains no package lockfile, so dependency versions and transitive dependency integrity are not reproducibly fixed by this artifact.
This is a supply-chain weakness rather than evidence that any currently declared dependency is malicious. Exploitation requires compromise, replacement, dependency confusion, or an unsafe future publication affecting a package that installation resolves.
Attack Path
- An attacker compromises or gains control of the unpinned
skillsregistry package, one of the declared dependencies, or a relevant transitive dependency. - The attacker publishes a malicious version that remains compatible with the unpinned invocation or caret version range.
- A user follows the documented command or run ...[truncated 1096 chars]
- An attacker compromises or gains control of the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the package executed by
npxto an exact, reviewed version, for examplenpx --yes skills@X.Y.Z ..., after confirming the package identity and publisher. - Replace the
<owner/repo>placeholder with a verified repository owner and repository name. Where supported, bind installation to an immutable commit digest or signed release. - Pin direct dependencies to exact versions rather than caret ranges.
- Generate, review, and commit a lockfile so direct and transitive dependency versions and integrity hashes are reproducible.
- Use
npm ciin CI and deployment workflows to enforce the reviewed lockfile. - Disable package lifecycle scripts during dependency acquisition where they are unnecessary, such as with
npm ci --ignore-scripts, and explicitly run only reviewed build steps afterward. - Add automated dependency scanning, provenance verification, lockfile integrity checks, and controlled update review.
- Run package installation with a non-privileged account in an isolated environment with minimal filesystem, credential, and network access.
- Pin the package executed by
