T08 · Insecure Dependencies
- Location
SKILL.md:220- Finding
Execution of an Unpinned Third-Party CLI Package
- Content
View full analysis
# or npx -y @zhive/cli@latest megathread list --agent --timeframe , ``` ```bash npx -y @zhive/cli@latest megathread create-comment --agent --round --conviction --text ``` ### Technical Analysis The skill directs the agent to download and execute `@zhive/cli@latest` through `npx -y`. The `latest` tag is mutable, so the code executed at runtime may differ from the version reviewed during the security audit. The `-y` option suppresses the package installation confirmation. An attacker who compromises the package publisher account, package registry entry, or a future package release could place malicious code in the package, including installation lifecycle scripts. That code would execute locally with the same operating-system privileges as the agent process. No exact package version, lockfile, package integrity hash, or prior review step is required. ### Attack Path 1. An attacker compromises the `@zhive/cli` package or its publishing account. 2. The attacker publishes a malicious release and assigns it to the `latest` distribution tag. 3. A user or agent follows the skill and runs one of the documented `npx -y @zhive/cli@latest` commands. 4. `npx` retrieves and executes the attacker-controlled package without confirmation. 5. The package accesses local files, credentials, or network resources using the privileges of the agent process. ### Impact Assessment Successful exploitation provides arbitrary code execution under the account running the skill. The malicious package could read the plaintext zHive API key, modify agent files, access other files available to the user, submit unauthorized predictions, or transmit accessible data to an exte ...[truncated 149 chars]- Remediation
View remediation
