T08 · Insecure Dependencies
- Location
SKILL.md:129- Finding
Execution of Mutable and Inconsistently Identified npm Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:129-145; secondary conflicting dependency reference atreference/tools.md:28
Vulnerability Type: Supply-chain compromise through mutable package installation
Risk Level: HighVulnerable Code
From
SKILL.md:bash npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.orgbash flyai --helpbash sudo npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.orgFrom
reference/tools.md:bash npx @anthropic-ai/flyai-cli@latestTechnical Analysis
The Skill installs or executes an npm package using the mutable
@latesttag. No exact version, lockfile, integrity hash, signature, or package-provenance check is required. As a result, the code executed at runtime can differ from the package that existed when the Skill was audited.The documented package identity is also inconsistent:
SKILL.mdinstalls@fly-ai/flyai-cli.reference/tools.mdexecutes@anthropic-ai/flyai-cli.
This inconsistency increases the chance of dependency confusion, package impersonation, or accidental execution of an unrelated package. npm installation may execute package lifecycle scripts, while
npxdownloads and runs package code directly.Attack Path
- An attacker compromises one of the referenced npm packages, its publisher account, or the associated namespace.
- The attacker publishes a malicious release and causes it to resolve through the
latesttag. - The Agent follows the Skill instructions and runs
npm installornpx. - npm downloads the mutable package without an integrity policy tied to a reviewed artifact.
- Malicious lifecycle scripts or CLI entry points execute on the local host.
- If the privileged fallback is used, the malicious code executes with root permissions.
Impact Assessment
Successful exploitation can provide arbitrary code e ...[truncated 448 chars]
- Remediation
View remediation
Remediation Suggestions
- Establish and document a single verified official package identity.
- Pin the dependency to an exact audited version rather than
@latest. - Use a project-local dependency and commit a lockfile with package integrity metadata.
- Verify package provenance, publisher identity, signatures, and registry integrity before execution.
- Avoid automatic package installation during every Skill invocation.
- Replace
npx @package@latestwith a locally installed, pinned executable. - Disable or explicitly review npm lifecycle scripts where feasible.
- Remove the privileged installation fallback and run the package under a restricted, non-administrative account.
