T08 · Insecure Dependencies
- Location
SKILL.md:92- Finding
Unpinned Third-Party npm Package Download and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 92–95
Vulnerability Type: Unpinned third-party package execution
Risk Level: HighVulnerable Code
bash # Extract from specific directory npx design-extractor frontend/src # Extract from current project npx design-extractor .Technical Analysis
The documented commands use
npxto executedesign-extractorwithout specifying an exact package version or verifying package integrity. If the package is not already installed locally,npxmay retrieve the current package release from the configured npm registry and execute it immediately.Consequently, the code executed during extraction can differ from the content reviewed when this Skill was published. The project does not include a lockfile, integrity hash, vendored implementation, or executable source that would constrain or permit review of the effective payload. This is an insecure dependency pattern; it does not establish that the current upstream package is malicious.
Attack Path
- An attacker compromises the npm package, its publisher account, or the relevant package-distribution channel.
- The attacker publishes a modified package version containing a malicious installation hook or runtime payload.
- A user or AI agent follows the Skill instructions and runs
npx design-extractor .. npxdownloads the mutable package version and executes it with the invoking process's privileges.- The package can inspect the current project and potentially read, modify, or delete any other files accessible to that account. It can also initiate network connections or launch child processes unless separately sandboxed.
Impact Assessment
Successful exploitation would provide code execution under the account running
npx. The reachable scope may include the complete target repository, environment variables available to the process, developer credentials stored in accessible ...[truncated 309 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact, reviewed version, such as
npx --no-install design-extractorafter a controlled installation from a lockfile. - Commit an npm lockfile containing registry-resolved integrity hashes and use
npm cifor reproducible installation. - Do not permit
npxto download packages automatically during Skill execution. - Vendor or include the extractor implementation in the audited Skill package so its effective behavior can be reviewed.
- Verify package provenance using registry signatures, trusted publishing metadata, and checksum or integrity validation.
- Run extraction in a sandbox with minimal filesystem access, no unnecessary credentials, restricted network access, and no elevated privileges.
- Review package lifecycle scripts and disable them where they are unnecessary, for example through an appropriately assessed
--ignore-scriptsinstallation policy.
- Pin the dependency to an exact, reviewed version, such as
