T08 · Insecure Dependencies
- Location
README.en.md:105- Finding
Unpinned Third-Party Package Execution During Recommended Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.en.md:105andREADME.md:108
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
bash npx skills add https://github.com/helloo1568/image-ppt --skill image-pptTechnical Analysis
The recommended installation command invokes an unpinned third-party npm package through
npx. If the package is not already available locally,npxmay retrieve its current published version and execute it immediately. The command does not specify an audited package version or validate the downloaded package using a cryptographic hash.The referenced GitHub repository is also not pinned to an immutable release tag or commit hash. Therefore, both the installer behavior and the repository content can change after this Skill has been audited. This creates a supply-chain trust boundary in which future installation behavior depends on mutable external resources.
No evidence indicates that the currently documented package or repository is malicious. The vulnerability is the unsafe, mutable dependency-execution pattern.
Attack Path
- An attacker compromises the npm account, package publication process, GitHub account, or referenced repository.
- The attacker publishes a malicious version of the unpinned
skillspackage or modifies the repository content. - A user follows the recommended installation instructions and runs the documented
npxcommand. npxdownloads and executes the altered installer package.- The installer processes attacker-controlled repository content and may execute malicious actions with the privileges of the user running the command.
Impact Assessment
Successful exploitation could permit arbitrary command execution under the installing user's account. Depending on that account's permissions and the behavior of the compromised installer, an attacker could read or modify user-accessible files, ...[truncated 467 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the npm installer to an exact, reviewed version, for example by using an explicit package version rather than the latest available release.
- Pin the GitHub source to an immutable, reviewed commit hash or signed release tag.
- Publish and verify cryptographic checksums for downloaded Skill content.
- Prefer a download-and-review workflow over direct remote package execution.
- Use npm lockfiles and integrity metadata where the installation environment supports them.
- Document the expected files and hashes so users can verify the package before enabling the Skill.
- Recommend running installation with a non-privileged account in a restricted environment.
