T08 · Insecure Dependencies
- Location
scripts/generate_spec.py:173- Finding
Unpinned Runtime Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
scripts/generate_spec.py, lines 173–187
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
python def screenshot_html(html_path, output_path): """使用 Playwright 截图 HTML""" try: subprocess.run([ 'npx', 'playwright', 'screenshot', '--wait-for-timeout', '2000', '--full-page', html_path, output_path ], check=True, timeout=60) return True except Exception as e: print(f"截图失败:{e}") return FalseTechnical Analysis
The script invokes Playwright through
npxwithout specifying a package version, requiring a lockfile, verifying package integrity, or using--no-install. If Playwright is not already installed locally,npxmay resolve, download, and execute a package using the caller's npm registry configuration.Consequently, the reviewed source code does not fully determine the code that executes at runtime. A compromised public package release, transitive dependency, package registry, registry configuration, or dependency-resolution environment could cause attacker-controlled package lifecycle code or CLI code to run.
The invocation uses an argument array rather than a shell command, so the observed issue is not shell command injection. The risk arises from mutable and insufficiently constrained dependency resolution.
Attack Path
- A user invokes the skill to generate a requirements document.
- The script reaches
screenshot_html(). - The host does not have a verified local Playwright executable available to
npx, or npm resolution is otherwise influenced by attacker-controlled registry configuration. npxresolves or downloads the unpinned Playwright package and its dependency tree.- A compromised package lifecycle script or executable runs under the invoking user's account.
- The malicious dependency can act with the same filesystem, ...[truncated 553 chars]
- Remediation
View remediation
Remediation Suggestions
- Declare Playwright at an exact reviewed version in the project's dependency manifest and commit the corresponding lockfile.
- Install dependencies during a controlled deployment or build phase rather than downloading packages while processing user documents.
- Invoke only the verified project-local executable and disable installation during execution, for example with
npx --no-install playwright .... - Enforce lockfile integrity in deployment, such as using
npm ciagainst an approved registry. - Pin and audit transitive dependencies, and enable dependency integrity and vulnerability checks in CI.
- Consider using the pinned Python Playwright package and browser binaries installed through a controlled provisioning process.
- Run document generation in a sandbox with restricted filesystem and network access to limit the impact of any future dependency compromise.
