T08 · Insecure Dependencies
- Location
README.md:23- Finding
Unpinned Global Installation of a Third-Party npm CLI
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 23–28
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumVulnerable Code
bash # Via agentskills-cli npm install -g @jahonn/agentskills-cli agentskills install ./research-agent-skill -t all # Via ClawHub clawhub install research-agentTechnical Analysis
The documented installation procedure instructs users to install
@jahonn/agentskills-cliglobally without specifying an exact version or verifying package integrity. npm will therefore resolve the registry version associated with the default distribution tag at installation time.The audited project does not include the CLI source, a lockfile, an integrity hash, or provenance information that would allow users to reproduce or verify the installed artifact. In addition, npm installation can execute package lifecycle scripts unless explicitly disabled. A compromised package account, registry release, or transitive dependency could consequently execute arbitrary commands with the privileges of the user running the installation.
Using
-gincreases exposure by installing an executable into the user's global npm environment. This does not inherently grant administrative privileges, but any malicious installation behavior receives all filesystem, process, network, credential, and configuration access already available to that user.The
clawhub installalternative is also unpinned, but the available project contents do not establish its package-resolution or integrity-verification behavior. Therefore, the confirmed finding is specifically based on the npm installation command.Attack Path
- An attacker compromises the npm publisher account, package release process, package contents, or a dependency used by
@jahonn/agentskills-cli. - The attacker publishes a malicious version under the package's active distribution tag.
- A user follows the README and runs `npm install -g @j ...[truncated 1303 chars]
- An attacker compromises the npm publisher account, package release process, package contents, or a dependency used by
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed exact version rather than relying on a mutable distribution tag:
bash npm install -g @jahonn/agentskills-cli@X.Y.Z -
Prefer a project-local, lockfile-controlled installation over a global installation. Commit the resulting lockfile so dependency versions and integrity hashes are reproducible.
-
Publish and verify package provenance, checksums, signatures, or registry attestations before installation.
-
Audit the package's lifecycle scripts, bundled files, executable entry points, and transitive dependency graph before recommending it.
-
Where compatible, suppress lifecycle scripts during installation:
bash npm install --ignore-scripts @jahonn/agentskills-cli@X.Y.ZOnly invoke reviewed package functionality afterward.
-
Run installation and CLI operations in a least-privileged, isolated environment without unnecessary credentials or access to sensitive repositories.
-
Document the expected publisher, exact package version, integrity-verification procedure, and upgrade-review process.
-
Pin or otherwise authenticate the ClawHub artifact as well if that ecosystem supports versions, digests, signatures, or provenance verification.
-
