T08 · Insecure Dependencies
- Location
SKILL.md:44- Finding
Unpinned npm Package Is Downloaded and Executed Through npx
- Content
View full analysis
``` ### Technical Analysis The documented audit command invokes an npm package without specifying an exact version, integrity hash, or trusted lockfile. Depending on the local npm environment, `npx` can retrieve the currently published package from the configured registry and execute it immediately. Consequently, the code executed by this command can change after the Skill has been reviewed. If the package, publisher account, registry configuration, or dependency chain is compromised, invoking the documented command could run attacker-controlled package code. Package lifecycle scripts and the CLI entry point may execute with the same operating-system privileges as the user or agent running the Skill. The reviewed project does not provide a package manifest, lockfile, vendored implementation, checksum, or other integrity control that establishes which version will execute. This is a supply-chain exposure; the reviewed files do not establish that the current package is malicious. ### Attack Path 1. An attacker compromises the npm publisher account, package, transitive dependency, or registry resolution path for `@claws-shield/cli`. 2. The attacker publishes or serves a modified package version containing malicious lifecycle or CLI code. 3. A user or AI agent follows the command documented in `SKILL.md`. 4. `npx` resolves and potentially downloads the mutable package version. 5. The malicious package executes with the privileges and environment of the invoking process. 6. The package can access files available to that process, including the source tree supplied for auditing, and may access the network if the runtime environment permits it. ### Impact Assessment Successful exploitation can provide arbitrary code execution with the ...[truncated 409 chars]- Remediation
View remediation
