T08 · Insecure Dependencies
- Location
README.md:8- Finding
Unpinned Package Execution in Documented Installation Command
- Content
View full analysis
Vulnerability Details
File Location:
README.md, line 8
Vulnerability Type: Unpinned third-party installer and mutable Skill source
Risk Level: MediumVulnerable Code
bash npx skills add kirorab/12306-skillTechnical Analysis
The documented installation command invokes the
skillsnpm package throughnpxwithout specifying an exact package version or verifying package integrity. Depending on the local npm environment,npxmay retrieve and execute the latest available version of that package.The referenced
kirorab/12306-skillsource is also not pinned to a reviewed commit hash. Consequently, both the installer and the installed Skill may change after this audit. This creates a supply-chain trust boundary in which newly published or compromised upstream content can execute during installation without being identical to the audited code.The audited runtime scripts themselves did not contain command execution, persistence, credential access, obfuscation, or malicious payload retrieval. The risk is specifically associated with the installation procedure documented in the README.
Attack Path
- An attacker compromises the npm account or publishing pipeline associated with the unpinned
skillspackage, or compromises the referenced Skill repository. - The attacker publishes a malicious package version or modifies the repository contents to include installation-time or runtime code execution.
- A user follows the documented
npx skills add kirorab/12306-skillcommand. npxdownloads and executes the currently resolved installer package, which may differ from the version originally reviewed.- The installer retrieves the mutable Skill source and executes or installs attacker-controlled content.
- The malicious code runs with the privileges of the user performing the installation.
Impact Assessment
Successful exploitation can provide arbitrary code execution under the installing user's account. The acces ...[truncated 394 chars]
- An attacker compromises the npm account or publishing pipeline associated with the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the installer package to an exact, reviewed version rather than allowing
npxto resolve the latest release:bash npx --yes skills@<reviewed-exact-version> add kirorab/12306-skill - Pin the Skill source to a reviewed commit hash or immutable release tag instead of a mutable repository reference.
- Publish and verify cryptographic checksums or signatures for the installer and Skill artifact.
- Use a lockfile or an equivalent reproducible dependency mechanism wherever the installation workflow supports one.
- Run installation with a non-privileged account in an isolated environment.
- Review newly resolved installer and Skill versions before upgrading rather than relying on implicit latest-version resolution.
- Pin the installer package to an exact, reviewed version rather than allowing
