T08 · Insecure Dependencies
- Location
README.md:42- Finding
Unpinned Third-Party Components in Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 42–46
Vulnerability Type: Unpinned third-party dependency and mutable source reference
Risk Level: MediumVulnerable Code Snippet:
markdown ## Setup ```bash npx skills add himself65/finance-skills --skill options-payofftext ### Technical Analysis The documented setup command invokes `npx` without pinning the `skills` package to an exact, audited version. Depending on the local npm configuration and cache state, `npx` can download and execute the version currently resolved from the package registry. The `himself65/finance-skills` source reference is also not pinned to an immutable commit hash or verified release artifact. Consequently, the components installed or executed in the future may differ from those reviewed during this audit. This creates a supply-chain trust boundary in which mutable upstream content can be executed during installation. Exploitation requires compromise or malicious control of a relevant upstream package, repository, maintainer account, release process, or name-resolution source; no such compromise was observed in the audited project itself. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, the referenced source repository, or another relevant upstream publishing channel. 2. The attacker publishes malicious content under the same mutable package or repository reference. 3. A user follows the documented setup instructions and runs the `npx skills add ...` command. 4. `npx` resolves and executes the unpinned package, which then retrieves or installs the mutable repository content. 5. The malicious component executes with the permissions of the user running the command. ### Impact Assessment Successful exploitation could permit arbitrary code execution under the installing user's account. The resulting scope may include reading or modifying files accessible to that user, a ...[truncated 467 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the npm package invoked through
npxto an exact, reviewed version rather than relying on the registry's current resolution:bash npx skills@EXACT_AUDITED_VERSION add himself65/finance-skills@VERIFIED_COMMIT --skill options-payoff - Replace the mutable repository reference with a full, verified commit hash or a cryptographically signed immutable release.
- Publish expected checksums for downloaded artifacts and verify them before installation or execution.
- Use npm lockfiles and integrity metadata where the installation workflow supports them.
- Review the selected package version and repository revision for lifecycle scripts or other install-time execution.
- Run installation with least privilege in an isolated environment, without unnecessary secrets or credentials.
- Document the trusted publisher, exact version, commit identifier, and verification procedure so users can confirm that they are installing the audited artifact.
- Pin the npm package invoked through
