T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party npm Package Is Installed and Executed Without Integrity Verification
- Content
View full analysis
``` ### Technical Analysis The Skill delegates its entire implementation to the externally distributed `zhihu-cli` npm package. The reviewed project does not include that package's source code, an exact pinned version, a lockfile, a package integrity hash, or a reference to a verified source repository. Running `npm install -g zhihu-cli` can execute npm lifecycle scripts and installs executable package content globally for the current user or installation environment. The `npx zhihu-cli ` alternative is especially sensitive because `npx` may download and immediately execute the package when it is not already available locally. Because no immutable version or integrity constraint is specified, the code executed by future users can differ from the code that existed when this Skill was reviewed. Package-account compromise, malicious version publication, dependency compromise, or package-name takeover could therefore introduce arbitrary executable code without requiring changes to this repository. The audit found no evidence that the current npm package is malicious. The vulnerability is the Skill's unsafe trust and execution model and the inability to audit the implementation from the supplied project. ### Attack Path 1. An attacker compromises the npm publisher account, takes control of the package name, or compromises a transitive dependency. 2. The attacker publishes a modified package version containing a malicious lifecycle script or runtime payload. 3. A user follows the Skill instructions and runs either `npm install -g zhihu-cli` or `npx zhihu-cli `. 4. npm retrieves the mutable package from the registry without validating it against a project-spe ...[truncated 890 chars]- Remediation
View remediation
