T08 · Insecure Dependencies
- Location
scripts/create-dca.js:7- Finding
Execution of Unbundled Dependencies Outside the Audited Skill
- Content
View full analysis
Vulnerability Details
File Location:
scripts/create-dca.js:7-12,scripts/list-strategies.js:6-11,scripts/pause-strategy.js:6-9, andscripts/resume-strategy.js:6-9
Vulnerability Type: Untrusted external code dependency
Risk Level: MediumVulnerable Code
scripts/create-dca.js:7-12:js const path = require('path'); const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared'); const { createStrategy } = require(path.join(sharedDir, 'services')); const { formatError } = require(path.join(sharedDir, 'errors')); const { resolveToken } = require(path.join(sharedDir, 'price-service'));scripts/list-strategies.js:6-11:js const path = require('path'); const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared'); const { listStrategies } = require(path.join(sharedDir, 'services')); const { formatError } = require(path.join(sharedDir, 'errors')); const { formatStrategy } = require(path.join(sharedDir, 'formatter'));scripts/pause-strategy.js:6-9:js const path = require('path'); const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared'); const { pauseStrategy } = require(path.join(sharedDir, 'services')); const { formatError } = require(path.join(sharedDir, 'errors'));scripts/resume-strategy.js:6-9:js const path = require('path'); const sharedDir = path.resolve(__dirname, '..', '..', '..', 'shared'); const { resumeStrategy } = require(path.join(sharedDir, 'services')); const { formatError } = require(path.join(sharedDir, 'errors'));Technical Analysis
Every executable script imports JavaScript modules from a
shareddirectory located three levels above the Skill directory. These modules are outside the supplied and audited project artifact. Their source, version, integrity, installation process, and authorization behavior therefore cannot be verified.Node.js executes top-level module code ...[truncated 2292 chars]
- Remediation
View remediation
Remediation Suggestions
- Move all required implementation modules into the audited Skill package so that the complete runtime behavior is reviewable.
- If shared code must remain external, distribute it as a trusted package with an exact version, a committed lockfile, and package-integrity verification.
- Verify the canonical path and integrity hash of every dependency before loading it, and terminate execution if verification fails.
- Ensure the dependency directory and its parent directories are owned by a trusted account and are not writable by unprivileged users or unrelated Skills.
- Document the complete dependency installation and update process, including the provenance of the shared modules.
- Include and audit the authorization logic used to associate
telegramIdvalues with strategy records. - Add tests proving that the implementation performs simulation-only operations and cannot initiate on-chain transactions.
- Run the scripts under a least-privilege account with restricted filesystem, environment-variable, credential, and network access to reduce the impact of a compromised module.
