T08 · Insecure Dependencies
- Location
SKILL.md:30- Finding
Execution of an Unpinned npm Package
- Content
View full analysis
` (no install needed; npx fetches it on first use). Requires Node.js 18+. If `npx postbridge-cli` is unavailable for any reason, fall back to the bundled script at `/scripts/post-bridge.js` (same commands and flags). ``` ### Technical Analysis The Skill directs the Agent to run `npx postbridge-cli` without specifying an exact package version or verifying package integrity. When the package is absent from the local cache, `npx` retrieves the registry-selected release and executes its installation and runtime code. This creates a mutable supply-chain execution path: the code actually executed can change after the Skill has been audited. The bundled `scripts/post-bridge.js` implementation is available and auditable, but the documentation treats remote npm execution as the preferred path and the bundled script only as a fallback. A compromised npm publisher account, malicious future package release, registry compromise, or dependency-chain compromise could therefore introduce arbitrary code without any modification to this repository. ### Attack Path 1. An attacker compromises the npm account, release process, or dependency chain associated with `postbridge-cli`. 2. The attacker publishes a malicious version under the legitimate package name. 3. A user or Agent follows `SKILL.md` and invokes `npx postbridge-cli`. 4. `npx` resolves and downloads the malicious release because no exact version or integrity value is required. 5. The package executes with the privileges of the invoking user or Agent. 6. The malicious code ...[truncated 830 chars]- Remediation
View remediation
``` 2. If npm execution is required, pin an exact audited version rather than allowing registry resolution of the latest release: ```bash npx --yes postbridge-cli@ ``` 3. Verify package provenance and integrity before execution. Maintain an approved version and expected package hash in the Skill documentation or installation process. 4. Use a lockfile and a controlled installation step instead of downloading executable code during each task. 5. Review new releases before updating the pinned version. 6. Run the CLI with only the environment variables and filesystem access needed for the requested operation. ]]>
