T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Execution of an Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:10-15, 26-30, 36-46;references/cli-command-map.md:5-56
Vulnerability Type: Unpinned third-party dependency and mutable package execution
Risk Level: HighThe Skill instructs the Agent to install and execute the npm package
daisowithout specifying an exact version, lockfile, or integrity hash.Vulnerable Code
SKILL.md:10-15:yaml install: - kind: node package: daiso bins: - daisoSKILL.md:26-30:bash npx daiso health npx daiso url npx daiso helpSKILL.md:36-46:bash npx daiso products 수납박스 --json npx daiso stores 강남역 --limit 5 --json npx daiso inventory 1034604 --keyword 강남역 --json npx daiso display-location 1034604 04515 --json npx daiso gs25-products 콜라 --limit 10 --json npx daiso gs25-stores 강남 --limit 10 --json npx daiso gs25-inventory 오감자 --storeKeyword 강남 --storeLimit 10 --json npx daiso seveneleven-products 삼각김밥 --size 10 --json npx daiso seveneleven-stores "안산 중앙역" --limit 10 --json npx daiso emart24-products 커피 --pageSize 10 --json npx daiso lottemart-products 콜라 --storeName 강변점 --area 서울 --jsonThe same unpinned execution pattern appears throughout
references/cli-command-map.md:5-56, including:bash npx daiso products 수납박스 --json npx daiso cu-inventory 과자 --storeKeyword 강남 --json npx daiso get /api/seveneleven/inventory --keyword 핫식스 --storeKeyword "안산 중앙역" --storeLimit 10 --json npx daiso get /api/oliveyoung/products --keyword 선크림 --size 10 --json npx daiso get /api/cgv/timetable --playDate <YYYYMMDD> --theaterCode <theaterCode> --json npx daiso healthTechnical Analysis
A bare invocation such as
npx daisoresolves the package through the configured npm registry and may download it when it is not already installed. Because no exact version or verified integrity value is specified, the code executed during future Skill runs can differ from the code that existed when the Skill was reviewed.The artifa ...[truncated 2344 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed exact version in the installation metadata and every executable example, rather than resolving the latest release:
yaml install: - kind: node package: daiso@1.0.6 bins: - daisobash npx --yes daiso@1.0.6 health -
Do not rely on version pinning alone. Commit a lockfile containing npm integrity hashes and install with a deterministic command such as
npm ci. -
Review and retain the source corresponding to the pinned release. Where practical, vendor the audited implementation or publish it through a controlled internal registry.
-
Verify package provenance and integrity before execution. Use npm provenance information, registry signatures where supported, and an approved checksum or integrity policy.
-
Audit direct and transitive dependencies for known vulnerabilities and unexpected lifecycle scripts. Repeat this review before approving any version update.
-
Disable package lifecycle scripts with
--ignore-scriptswhen the package remains functional without them. If scripts are required, review each script before permitting execution. -
Execute the CLI in a restricted environment with least privilege:
- Use a dedicated unprivileged account or sandbox.
- Expose only required files and environment variables.
- Remove unrelated credentials from the process environment.
- Restrict outbound network access to documented service endpoints.
- Avoid running the Skill from privileged or sensitive working directories.
-
Add an explicit update process requiring source review, integrity verification, testing, and approval before changing the pinned version.
-
