T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Third-Party Packages Are Downloaded and Executed Through npx
- Content
View full analysis
" [options] ``` ``` ### Technical Analysis The documented commands invoke `screencli` and `skills` through `npx` without specifying exact package versions or integrity hashes. If a package is not already available locally, `npx` may retrieve it from the configured npm registry and immediately execute it. Consequently, the executable code is not fixed to the version reviewed when this Skill was published. A later malicious release, compromised maintainer account, registry compromise, or compromised transitive dependency could change the behavior of these commands without any modification to this repository. This repository contains documentation only and does not contain the implementation of the invoked CLI. The actual package behavior therefore cannot be verified from the audited files. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, its dependency chain, or the registry resolution path. 2. The attacker publishes a malicious version under a package name used by the documented commands. 3. A user or AI Agent follows the Skill and runs an unpinned `npx` command. 4. `npx` resolves and downloads the cu ...[truncated 761 chars]- Remediation
View remediation
