T08 · Insecure Dependencies
- Location
SKILL.md:52- Finding
Unpinned Runtime Dependency Installation Creates a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 52-58
Vulnerability Type: Unpinned third-party dependency installed automatically at runtime
Risk Level: MediumVulnerable Code
bash ### Step 3 — Auto-install dependency if missing This installs the package **locally inside the skill folder** only. ```bash if [ ! -d "$SKILL_DIR/node_modules/@google-cloud/text-to-speech" ]; then npm install @google-cloud/text-to-speech --prefix "$SKILL_DIR" --silent fitext ### Technical Analysis The Skill instructs the Agent to install `@google-cloud/text-to-speech` from the public npm registry automatically when the dependency is absent. It does not specify an exact reviewed version, enforce a lockfile, verify package integrity, or disable package lifecycle scripts. Consequently, the code executed by a first-time installation can change independently of the reviewed Skill. A compromised future release, compromised maintainer account, registry incident, or malicious transitive dependency could introduce code that executes during installation or when the package is loaded by `scripts/gtts.js`. Installing into a local directory limits where package files are stored, but it does not sandbox npm or package lifecycle scripts. Such scripts inherit the permissions, environment, network access, and filesystem access of the Agent process. ### Attack Path 1. The Skill runs in an environment where `node_modules/@google-cloud/text-to-speech` is absent. 2. An attacker compromises a future package release, a transitive dependency, or the relevant package publishing account. 3. The Agent executes the unversioned `npm install` instruction. 4. npm resolves the currently published package graph rather than a previously audited graph. 5. Malicious installation code or imported runtime code executes with the privileges of the Agent process. 6. That code can access data and resources available to the process, p ...[truncated 520 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
@google-cloud/text-to-speechto an exact, reviewed version instead of resolving the latest release. - Commit a generated lockfile and use
npm ciso the installed dependency graph is reproducible. - Use npm integrity metadata and review both direct and transitive dependency changes before updating.
- Use
npm ci --ignore-scriptswhere dependency functionality does not require lifecycle scripts. - Prefer packaging audited dependencies with the Skill or performing dependency installation during a trusted build phase rather than during Skill execution.
- Run installation and execution in a sandbox with minimal filesystem access, restricted environment variables, and outbound network access limited to required Google and npm endpoints.
- Avoid
--silentfor security-sensitive installation operations so relevant warnings and failures remain visible in audit logs.
- Pin
