T08 · Insecure Dependencies
- Location
SKILL.md:48- Finding
Execution of an Unpinned Third-Party CLI Package
- Content
View full analysis
--type stock ``` ```bash # Single stock npx daxiapi-cli@latest stock info# Multiple stocks npx daxiapi-cli@latest stock info ,, ``` The same mutable package reference is used for other operations, including: ```bash npx daxiapi-cli@latest klinenpx daxiapi-cli@latest report financenpx daxiapi-cli@latest stock capital-flownpx daxiapi-cli@latest sector heatmap --order cs --limit 20 ``` ### Technical Analysis The Skill repeatedly invokes `daxiapi-cli` through `npx` using the mutable `@latest` version selector. Depending on the local npm configuration and cache state, `npx` can download the selected package and execute its code immediately. Because `@latest` can resolve to a different release after the Skill has been audited, the effective executable payload is not fixed by the reviewed project. The project provides no exact version, lockfile, integrity hash, vendored implementation, publisher verification procedure, or other mechanism for ensuring that the executed package is the version that was security-reviewed. This creates a third-party supply-chain boundary. A malicious or compromised future package release could execute arbitrary code with the privileges of the process running the Skill. The danger is amplified because the CLI is intentionally given access to a DAXIAPI token. ### Attack Path 1. An attacker compromises the npm publisher account, the package repository ...[truncated 1441 chars]- Remediation
View remediation
``` 2. Maintain a lockfile and verify package integrity against an approved checksum or trusted artifact registry. 3. Document the expected npm package publisher, repository, package signature, and review process. 4. Prefer installing an approved version in a controlled build step rather than downloading executable code during every Skill invocation. 5. Disable or audit npm lifecycle scripts where operationally possible. 6. Run the CLI in a restricted environment with: - Minimum filesystem access. - Only the required environment variables. - Restricted outbound network access. - No administrator or root privileges. 7. Establish a dependency-update process that requires review and testing before changing the pinned version. 8. Rotate the DAXIAPI token if an untrusted or compromised package version may have been executed. ]]>
