T03 · Remote Payload Retrieval and Execution
- Location
reference/workflow.md:3- Finding
Mutable npm Package Is Retrieved and Installed Globally Before Searches
- Content
View full analysis
Vulnerability Details
File Location:
reference/workflow.md, lines 3-12;reference/tools.md, lines 24-30
Vulnerability Type: Unpinned remote dependency retrieval and execution
Risk Level: HighEvidence
markdown ### 前置步骤:安装/升级 FlyAI CLI 在执行任何搜索之前,**必须先执行安装命令**(无论是否已安装,确保为最新版本): ```bash npm install -g @fly-ai/flyai-cli@latest --registry=https://registry.npmjs.org💡 此命令会自动处理首次安装和版本升级,无需手动判断是否已安装。安装后验证:
bash flyai --helptext A separate tool reference names a different package: ```markdown ## FlyAI 核心能力 使用 `npx @anthropic-ai/flyai-cli@latest` 调用飞猪数据。 **常用命令**: - `search flights`: 搜索航班 - `search hotels`: 搜索酒店 - `search attractions`: 搜索景点 - `search restaurants`: 搜索餐厅Technical Analysis
The workflow directs the agent to retrieve the mutable
latestrelease of an npm package and install it globally before performing travel searches. npm installation can execute package lifecycle scripts, includingpreinstall,install, andpostinstall. Consequently, the code executed at runtime is not the code that existed when this skill was audited.No exact package version, integrity hash, lockfile, signature verification, or trusted publisher validation is specified. The documentation also inconsistently identifies the package as both
@fly-ai/flyai-cliand@anthropic-ai/flyai-cli. This ambiguity increases the chance that an operator or agent retrieves an unintended package.The use of global installation broadens the effect beyond the current project. It can replace a pre-existing
flyaiexecutable and affect subsequent sessions or unrelated projects.Attack Path
- An attacker compromises the npm publisher account, package repository, release pipeline, or one of the named package scopes.
- The attacker publishes a malicious release that becomes the package's
latestversion. - A user invokes the skill for an ordinary travel search.
- The workflow runs
npm install -g ...@latest. - npm downloads t ...[truncated 1104 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove automatic installation or upgrading from the skill's normal execution path.
- Require the CLI to be installed through a separate, explicit administrator-controlled setup process.
- Select one verified package identity and use it consistently throughout all documentation.
- Pin an exact reviewed version, for example
@fly-ai/flyai-cli@1.2.3, rather than@latest. - Verify package integrity against an independently published SHA-256 digest, signed provenance, or trusted package-lock entry.
- Disable npm lifecycle scripts during installation where the package supports operation without them:
bash npm install --ignore-scripts --save-exact @fly-ai/flyai-cli@1.2.3 - Prefer a project-local dependency over a global installation and invoke it through a fixed local path.
- Do not use
npx ...@latest, because it retains the same mutable remote-execution risk. - Document the expected publisher, repository, package digest, executable path, and release verification procedure.
