T08 · Insecure Dependencies
- Location
reference/workflow.md:5- Finding
Unpinned Global Dependency Installation with Optional Root Privileges
- Content
View full analysis
Vulnerability Details
File Location:
reference/workflow.md:5-8, 16-21
Vulnerability Type: Unsafe dependency installation and privilege escalation
Risk Level: HighVulnerable Code
bash npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.orgmarkdown | npm unavailable | Ask the user to install Node.js | | Insufficient permissions | Recommend `sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org` or use nvm | | Network problem | Recommend checking the network or changing the npm registry |Technical Analysis
The workflow requires installation or upgrade of
@fly-ai/flyai-cliusing the mutablelatesttag. No exact version, lockfile, package integrity hash, or release verification is specified. Consequently, the code executed by the Skill can change after the Skill itself has been reviewed.npm package installation can execute package lifecycle scripts such as
preinstall,install, andpostinstall. Global installation expands the modification scope beyond the project directory. The suggestedsudofallback is particularly dangerous because lifecycle scripts from the downloaded package can then execute with root privileges.Although the configured source is the official npm registry, that does not eliminate account compromise, malicious package updates, registry compromise, or upstream supply-chain risks.
Attack Path
- An attacker compromises the npm package, its maintainer account, or a future release published under the package name.
- The malicious release becomes the version selected by the
latesttag. - A user invokes the Skill, which requires installation or upgrade before performing a search.
- npm downloads the mutable release and executes its lifecycle scripts.
- If the normal global installation fails due to permissions, the workflow recommends repeating the operation with
sudo. - The malicio ...[truncated 591 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version rather than using
@latest. - Verify package integrity using a lockfile, trusted checksum, or signed release metadata.
- Remove the instruction to install the package with
sudo. - Install the dependency locally in a dedicated project directory rather than globally.
- Run the CLI in a restricted container or sandbox with minimal filesystem and network permissions.
- Disable npm lifecycle scripts where feasible, for example by using
--ignore-scripts, after confirming that the package does not legitimately require them. - Do not automatically upgrade the dependency whenever the Skill runs. Require explicit user approval for installation and separately reviewed upgrades.
- Prefer a trusted, pre-provisioned tool interface whose version is controlled by the Agent runtime.
- Pin the CLI to a specifically reviewed version rather than using
