T08 · Insecure Dependencies
- Location
install.sh:5- Finding
Unpinned Global Installation of a Security-Sensitive Third-Party Package
- Content
View full analysis
/dev/null; then echo "📦 Installing kalshi-cli from npm..." npm install -g kalshi-cli else echo "✅ kalshi-cli is already installed" fi ``` The same unpinned installation is documented in `SKILL.md` and `README.md`: ```bash npm install -g kalshi-cli ``` ### Technical Analysis The installer resolves the current `kalshi-cli` release from the npm registry at installation time. It does not specify an exact audited version, verify a package integrity digest, validate package provenance, or use a lockfile. Consequently, the code executed by the installation can differ from the code reviewed with this Skill. npm packages can execute lifecycle scripts during installation. The globally installed CLI also subsequently receives access to the user's Kalshi authentication material and is authorized to place financial trades. Global installation increases the potential impact. Depending on the npm configuration and the way the script is invoked, package installation scripts may execute with the current user's privileges or elevated privileges. The external `kalshi-cli` implementation was not included in the audited project, so its behavior could not be verified. This finding does not establish that the current npm package is malicious. It identifies an unsafe trust and update model for a component with credential access and financial transaction capabilities. ### Attack Path 1. An attacker compromises the npm publisher account, package repository, release workflow, or another part of the package supply chain. 2. The attacker publishes a malicious release under the existing `kalshi-cli` package name. 3. A user runs `install.sh` or ...[truncated 1207 chars]- Remediation
View remediation
``` 2. Verify the downloaded package against an expected integrity digest and validate npm provenance before installation. 3. Review whether the package requires lifecycle scripts. Use `--ignore-scripts` if they are not essential. 4. Prefer a project-local or otherwise isolated installation over a global installation. 5. Do not instruct users to run the installer with `sudo` or as root. 6. Record the reviewed version and expected integrity value in the Skill package. 7. Re-audit the external CLI whenever the pinned version is updated, with particular attention to: - Credential loading and storage - Network destinations - Request signing - Trade confirmation behavior - Shell execution - npm lifecycle scripts 8. Consider requiring explicit user approval before installing external code rather than installing it automatically. ]]>
