T08 · Insecure Dependencies
- Location
SKILL.md:132- Finding
Unpinned Third-Party CLI and Unverified Browser Extension
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 132-143
Vulnerability Type: Unverified and mutable third-party dependencies
Risk Level: HighVulnerable Code
bash npm install -g @jackwener/openclitext https://github.com/jackwener/opencli/releases opencli-extension.zipThe same installation guidance is repeated at lines 167-174 and 191-198. Line 512 also recommends installing the mutable latest release:
bash npm install -g @jackwener/opencli@latestTechnical Analysis
The Skill requires a globally installed npm package without pinning an exact version. It also directs users to select an unversioned ZIP archive from a personal GitHub release page and manually load the extracted content as an unpacked Chrome extension. No cryptographic checksum, signature, immutable release URL, or reviewed extension manifest is supplied.
Because both installation sources are mutable, the code ultimately executed can change after the Skill itself has been audited. A global npm installation can execute package lifecycle scripts with the installing user's privileges and place executable files in a globally accessible command path. The manually loaded extension is especially sensitive because the documented functionality relies on reusing authenticated Chrome sessions across numerous websites.
Installing the CLI and extension is relevant to the declared content-fetching functionality, but the unpinned and unverified installation model grants substantially more trust than necessary. The recommendation to install
@latestfurther prevents users from reproducing an audited configuration.Attack Path
- An attacker compromises the npm publisher account, GitHub account, repository, release workflow, or downloadable release artifact.
- The attacker publishes a malicious package version or replaces the extension ZIP available from the generic releases page.
- A user follows the S ...[truncated 1218 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the npm dependency to a specific reviewed version instead of using an unqualified package name or
@latest. - Record and verify the npm package integrity hash before installation.
- Replace the generic GitHub releases link with an immutable, version-specific artifact URL.
- Publish a SHA-256 digest and, preferably, a verifiable digital signature for the extension archive.
- Include the reviewed extension source and manifest in the audit scope, or distribute it through a verified browser-extension marketplace.
- Document every requested extension permission and remove permissions not strictly required for selected platforms.
- Restrict extension access to explicitly selected domains rather than granting broad access to every supported platform.
- Avoid global installation where possible. Use a pinned project-local dependency, isolated runtime, or restricted container.
- Disable or review npm lifecycle scripts during installation and verify the package provenance before execution.
- Provide a controlled update process that requires review and integrity verification before users move to a newer release.
- Pin the npm dependency to a specific reviewed version instead of using an unqualified package name or
