T08 · Insecure Dependencies
- Location
SKILL.md:33- Finding
Unpinned npm Package Is Downloaded and Executed Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 33–43
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash # Audit by skill name npx skillguard-audit --name <skill-slug> # Audit local skill folder npx skillguard-audit --path ./my-skillbash # Start the API server npx skillguard-audit serve --port 3402Technical Analysis
The documented commands delegate all security-scanning and API-server functionality to the external
skillguard-auditnpm package without specifying an exact package version. When the package is unavailable locally,npxmay offer to download it from the configured npm registry and then execute its package lifecycle or CLI code.Consequently, the code executed by users is not immutable and may differ from the version that existed when this skill was audited. A compromised package release, package ownership transfer, registry compromise, or unsafe registry configuration could replace the expected scanner with attacker-controlled code.
The project contains only
SKILL.mdand does not include a local implementation against which the advertised scanning behavior can be verified.Attack Path
- An attacker compromises the
skillguard-auditpackage, its publisher account, or the package source selected by the user's npm configuration. - The attacker publishes a malicious version under the same package name.
- A user follows one of the documented unversioned
npx skillguard-auditcommands. npxresolves the current package version and, if it is not already available locally, downloads it from the configured registry.- The downloaded package executes with the permissions of the user running the command.
- Malicious package code can inspect supplied skill directories, read other files accessible to that user, initiate network connections, alter user-owned files, or execute addition ...[truncated 671 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to an exact, reviewed version rather than invoking an unconstrained package name.
- Prefer declaring the package in a local
package.json, committing a lockfile with integrity metadata, installing withnpm ci, and invoking the lockfile-resolved local binary. - Disable or avoid implicit package installation during execution. Ensure the command fails if the reviewed dependency is not already installed.
- Verify the package publisher, official repository, provenance attestations, and registry source before installation.
- Use npm integrity checks and a trusted registry configuration; review dependency and transitive-dependency changes before updating the lockfile.
- Execute the scanner with least privilege in an isolated environment with restricted filesystem access, limited environment variables, no unnecessary credentials, and controlled network access.
- Document the exact package version and source that correspond to the skill's reviewed release.
