T08 · Insecure Dependencies
- Location
scripts/render.mjs:11- Finding
Automatic Unpinned Dependency Installation Enables Supply-Chain Code Execution
- Content
View full analysis
Vulnerability Details
File Location:
scripts/render.mjs:11-34; duplicated inscripts/batch.mjs:11-34andscripts/themes.mjs:10-33
Vulnerability Type: Automatic installation of unpinned third-party dependencies
Risk Level: HighVulnerable Code
javascript async function loadBeautifulMermaid() { try { return await import('beautiful-mermaid'); } catch {} console.error('[beautiful-mermaid] Dependency not found. Installing automatically...'); try { execSync('npm install --no-fund --no-audit', { cwd: skillRoot, stdio: ['pipe', 'pipe', 'inherit'], timeout: 120000, }); console.error('[beautiful-mermaid] Installed successfully.\n'); } catch (e) { console.error(`[beautiful-mermaid] Auto-install failed: ${e.message}`); console.error(`Manual fix: cd ${skillRoot} && npm install`); process.exit(1); } try { const pkgPath = join(skillRoot, 'node_modules', 'beautiful-mermaid', 'dist', 'index.js'); return await import(pkgPath); } catch (e) { console.error(`[beautiful-mermaid] Failed to load after install: ${e.message}`); process.exit(1); } }Technical Analysis
All three executable scripts automatically invoke
npm installwhen the initial import ofbeautiful-mermaidfails. The audited project does not contain apackage.jsonor lockfile that pins the package version and integrity.Consequently, installation behavior is not reproducible or constrained to an audited dependency graph. npm may use package metadata or configuration from the surrounding environment, contact configured registries, and execute dependency lifecycle scripts. The
--no-auditoption also disables npm's vulnerability audit for this operation.Although the installation behavior is documented, it creates a supply-chain execution boundary without an approval step or integrity verification.
Attack Path
...[truncated 990 chars]
- Remediation
View remediation
Remediation Suggestions
- Add a minimal
package.jsonthat declaresbeautiful-mermaidat an exact reviewed version. - Commit a lockfile containing registry URLs and integrity hashes.
- Replace automatic
npm installwith a clear failure message and require explicit user approval before modifying dependencies. - In controlled deployments, install dependencies ahead of execution with
npm ci --ignore-scripts. - If lifecycle scripts are required, audit them and enable them only during a dedicated installation phase.
- Use a trusted registry allowlist and avoid inheriting uncontrolled npm configuration from parent directories or user-level configuration.
- Remove
--no-auditfrom approved installation workflows and run dependency vulnerability and provenance checks. - Apply the same correction consistently to
render.mjs,batch.mjs, andthemes.mjs.
- Add a minimal
