T08 · Insecure Dependencies
- Location
scripts/install_runtime.sh:10- Finding
Unpinned Runtime Dependencies Permit Mutable Supply-Chain Code
- Content
View full analysis
/dev/null 2>&1) fi (cd "$NODE_DIR" && npm install --silent puppeteer-core@24) ``` ### Technical Analysis The installer dynamically retrieves `pip`, `yt-dlp`, and `puppeteer-core` from external package registries. Neither the Python packages nor `pip` are version-pinned. The Puppeteer dependency is constrained only to major version 24 rather than an exact reviewed release. No lockfile, integrity hash, or package-signature verification is used. As a result, the code installed by this script can change without any corresponding change to the audited project. A compromised package registry, compromised maintainer account, malicious package release, or unexpectedly incompatible update could introduce code that was not present during review. This finding concerns unsafe dependency resolution rather than evidence that the currently named packages are malicious. ### Attack Path 1. An attacker compromises a relevant registry account or publishes a malicious release within the accepted version range. 2. A user follows the documented setup process and runs `scripts/install_runtime.sh`. 3. `pip` or `npm` resolves the mutable dependency to the attacker-controlled release. 4. The package is installed into the skill runtime. 5. Malicious package behavior executes during installation or when `yt-dlp` or Puppeteer is later loaded and invoked. ### Impact Assessment Malicious dependency code would generally execute with the privileges of the user running the installer or skill. It could access files readable by that user, make network requests, alte ...[truncated 305 chars]- Remediation
View remediation
