T08 · Insecure Dependencies
- Location
SKILL.md:82- Finding
Unpinned npm Package Execution via npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 82–88
Vulnerability Type: Supply-chain risk caused by unpinned, on-demand npm package execution
Risk Level: MediumVulnerable Code:
javascript // Submit trending tokens job await exec("npx tsx bin/acp.ts job create 0xe5B38F112b92Ce8F2103eDAbA7E9a9842f12d5f6 trending_tokens --requirements '{\"initiate_trending_altcoins_job\":true}'") // Check job status await exec("npx tsx bin/acp.ts job status 123456789") // Browse agents await exec("npx tsx bin/acp.ts browse trading")Technical Analysis
The documented commands execute
npx tsxwithout specifying an exact package version. Iftsxis unavailable locally,npxmay download and execute a package resolved from the configured npm registry. The artifact provides nopackage.json, lockfile, integrity metadata, or trusted-registry configuration to constrain that resolution.As a result, the code ultimately executed can change after the Skill has been reviewed. Registry compromise, dependency-account compromise, or manipulated package resolution could cause attacker-controlled package code to run with the invoking process's permissions.
The referenced local entry point,
bin/acp.ts, is also absent from the supplied artifact, which contains onlySKILL.md. Therefore, the advertised implementation cannot be audited or verified, and the examples do not operate as provided. This absence does not itself establish malicious behavior, but it prevents validation of the claimed paid-job and cryptocurrency operations.Attack Path
- An Agent or user follows one of the documented command examples.
- The system invokes
npx tsxwithout a pinned version. - If no trusted local installation is available,
npxresolves the package through the configured npm registry. - A compromised registry package, maintainer account, or package-resolution environment supplies attacker-controlled code ...[truncated 962 chars]
- Remediation
View remediation
Remediation Suggestions
- Add the referenced
bin/acp.tsimplementation to the package and subject it to security review. - Declare
tsxat an exact reviewed version inpackage.jsonand commit the corresponding lockfile. - Install dependencies in a controlled build step using lockfile enforcement, such as
npm ci, rather than permitting on-demand package retrieval during Skill execution. - Invoke the locally installed, pinned executable, such as
./node_modules/.bin/tsx, and disable automatic remote installation. - Enforce an approved npm registry and verify package integrity and provenance.
- Run the command with least privilege in a sandbox that restricts filesystem, environment-variable, credential, and network access.
- Require explicit user confirmation before submitting paid jobs, initiating trades, swaps, or performing any wallet-authorized operation.
- Validate agent addresses, service names, requirements, prices, and transaction details before requesting signatures or transferring funds.
- Add the referenced
