T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned npm Dependency Installation in Skill Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19
Vulnerability Type: Unpinned third-party dependency installation
Risk Level: Mediumbash npm install https-proxy-agentTechnical Analysis
The installation command does not specify an exact package version, lockfile, or integrity value. Consequently, npm resolves the package version available under the mutable
latestdistribution tag at installation time. The project also provides nopackage.jsonor lockfile to constrain or reproduce the dependency graph.Although
https-proxy-agentis a legitimate package, this installation pattern creates supply-chain exposure if a future release, package publication channel, maintainer account, or transitive dependency is compromised. npm lifecycle scripts associated with an installed package may execute during installation unless explicitly disabled.The referenced implementation,
scripts/youtube-openclaw-monitor.js, is absent from the supplied project, so the necessity and expected use of this dependency cannot be independently verified.Attack Path
- An attacker compromises the package publication channel, a maintainer account, a future package release, or a dependency in the resolved graph.
- The attacker publishes a malicious version selected by the unpinned installation command.
- A user follows the documented instructions and runs
npm install https-proxy-agent. - npm downloads the attacker-controlled release and may execute its lifecycle scripts.
- The malicious code executes with the privileges of the user running npm and may inspect files, network access, and environment variables available to that process.
Impact Assessment
Successful exploitation could execute arbitrary code with the invoking user's privileges. Within that scope, malicious dependency code could read or alter user-accessible files, initiate outbound network connections, modify project content, and access envi ...[truncated 283 chars]
- Remediation
View remediation
Remediation Suggestions
- Add a reviewed
package.jsonthat declares an audited, exact dependency version. - Generate and commit a lockfile containing resolved versions and integrity hashes.
- Replace ad hoc installation with
npm ciso installation fails if the manifest and lockfile disagree. - Review the selected package version and its transitive dependency graph before distribution.
- Use
npm ci --ignore-scriptswhen package lifecycle scripts are not required. - Configure npm to use a trusted registry and retain integrity verification.
- Include the referenced implementation in the project so auditors can verify why the dependency is required and how it is used.
- Add a reviewed
