T08 · Insecure Dependencies
- Location
SKILL.md:178- Finding
Unverified Mutable Remote Dependencies in a Privileged L0 Runtime
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:178-179andSKILL.md:293-296
Vulnerability Type: Unverified third-party dependency and Skill installation
Risk Level: MediumVulnerable Instructions
SKILL.md:178-179:text npm ci && npm run build https://zenheart.net/v2/faq/skills/zen-editorial-review https://zenheart.net/v2/faq/skills/zen-editorial-review/bundleSKILL.md:293-296:text npm ci && npm run build node dist/cli.js https://zenheart.net/#/faq#zenlinkTechnical Analysis
The Skill directs operators to obtain, build, and use Zenlink from an external site or site-hosted archive. It also directs them to install the
zen-editorial-reviewSkill from a remote URL. The audited artifact does not include these dependency sources, their lockfiles, cryptographic checksums, signatures, or immutable commit references.As a result, the effective code and instruction payload used at runtime can differ from what was available when this Skill was reviewed. The
npm cioperation may execute package lifecycle scripts from the externally obtained Zenlink source and its dependency tree. A remotely installed Skill can also introduce new Agent instructions that are outside this audit scope.HTTPS protects data in transit but does not establish artifact immutability. It does not protect against compromise of the hosting account, build pipeline, package registry, dependency publisher, or upstream source archive.
This issue is particularly sensitive because the documented runtime receives
ZENLINK_TOKENand operates as a Level-0 administrator with platform-wide governance capabilities.Attack Path
- An attacker compromises the hosted Zenlink archive, an upstream npm dependency, the dependency publication pipeline, or the remote editorial-review Skill bundle.
- The attacker replaces the expected resource with malicious code or malicious Agent instructions wh ...[truncated 1308 chars]
- Remediation
View remediation
Remediation Suggestions
- Vendor reviewed Zenlink source code, its package manifest, and its lockfile in the audited repository or distribute it through a controlled internal artifact registry.
- Pin every remote component to an immutable release, commit hash, or content-addressed artifact rather than a mutable URL.
- Publish SHA-256 checksums and cryptographic signatures for Zenlink archives and Skill bundles. Verify both before installation or execution.
- Pin
zen-editorial-reviewto a specific reviewed version and reject bundles whose digest does not match the approved value. - Inspect npm dependencies before permitting lifecycle scripts. Use
npm ci --ignore-scriptsfor initial verification, then explicitly execute only reviewed build steps. - Generate and review a software bill of materials and scan transitive dependencies for known vulnerabilities, dependency confusion, and unexpected package changes.
- Build external dependencies in an isolated environment without Level-0 credentials, production network access, SSH keys, or deployment secrets.
- Run the final client with least privilege and expose only the credentials and administrative operations required for the current task.
- Monitor dependency digests and require security review whenever a remote artifact, lockfile, or Skill bundle changes.
- Document a trusted rollback version and immediately rotate the Level-0 token if dependency compromise is suspected.
