T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Global Installation of an Unaudited Third-Party CLI Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 15
Vulnerability Type: Supply-chain exposure through an unpinned globally installed dependency
Risk Level: HighVulnerable Code Snippet:
bash npm install -g qwb-cliTechnical Analysis
The Skill instructs users or agents to install
qwb-cliglobally from the npm registry without specifying an exact version, integrity hash, verified publisher identity, trusted source repository, or lockfile. Consequently, the code installed at execution time can differ from the code that existed when the Skill was reviewed.The
-goption installs the package into the user's global npm environment. Package installation can also execute npm lifecycle scripts where permitted. Any malicious code introduced through package compromise, ownership transfer, dependency confusion, or a compromised transitive dependency would run with the privileges of the user performing the installation.This risk is particularly significant because the installed CLI is subsequently trusted to authenticate users, process passwords and verification codes, store a token in
~/.qwb/credentials.json, upload private audio and video, and communicate with remote services. The repository contains no CLI source, package manifest, lockfile, checksums, or signature information with which these behaviors can be independently verified.Attack Path
- An attacker compromises the
qwb-clinpm package, its publisher account, or one of its transitive dependencies. - The attacker publishes a malicious release under the same package name or causes a malicious dependency version to be resolved.
- A user or agent follows the Skill instruction and runs
npm install -g qwb-cli. - npm retrieves the mutable package version available at installation time and may execute its lifecycle scripts.
- Malicious code executes with the installing user's privileges.
- The compromise ...[truncated 1116 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a reviewed exact version, for example:
bash npm install -g qwb-cli@<reviewed-exact-version> -
Publish and verify the expected package integrity hash or signed release provenance before installation.
-
Document the official npm scope, publisher identity, and source repository so users can detect package substitution or ownership changes.
-
Include the CLI source or a reproducible build reference in the audited project.
-
Provide and audit a lockfile for all transitive dependencies.
-
Prefer a project-local or isolated installation over global installation, such as a dedicated container or restricted execution environment.
-
Disable npm lifecycle scripts during installation unless they are explicitly required and separately audited.
-
Run the CLI with only user-level permissions and restrict filesystem and network access to the minimum required destinations.
-
Protect
~/.qwb/credentials.jsonwith owner-only permissions, avoid exposing its contents in logs, and shorten or make configurable the documented 30-day token lifetime. -
Restrict API endpoint configuration to trusted HTTPS origins or clearly warn users before credentials are sent to a changed endpoint.
-
