T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party npm Package Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24–29 and 48–55
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
yaml install: - kind: node package: agentsec bins: - agentsec label: Install agentsec (npm)markdown The fastest path to a result — no install, no flags: ```bash npx agentsecThis scans every default skills directory on the machine — grouped by platform — plus any
./skillsfolder in the current project (up to two levels deep), and audits each installed skill against the OWASP Agentic Skills Top 10. Always try this first.text The document also recommends persistent global installation at lines 89–99: ```bash # bun (recommended) bun add -g agentsec # npm npm install -g agentsec # pnpm pnpm add -g agentsec # yarn yarn global add agentsecTechnical Analysis
The skill directs users or agents to retrieve and execute the
agentsecnpm package without pinning an exact audited version or supplying a lockfile, integrity hash, signature, or immutable source reference. Depending on localnpxbehavior and cache state,npx agentseccan download and execute the package version currently selected by the registry.Consequently, the code ultimately executed may differ from the artifact that was reviewed. Package lifecycle scripts and the CLI itself can execute with the privileges of the invoking user. The globally installed alternatives increase persistence and can expose subsequent invocations to a compromised release.
This is a supply-chain risk rather than evidence that the current
agentsecpackage is malicious. The reviewed project contains no bundled executable implementation with which to verify the package’s behavior.Attack Path
- An attacker compromises the npm package publisher, registry release process, or a transitive dependency used by a future package release.
- The attacker publishes a malicious version that ...[truncated 1125 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact reviewed version in all examples, such as
npx --yes agentsec@<exact-version>, and update the pin only after review. - Use a project-local dependency with a committed lockfile rather than encouraging unversioned, on-demand execution.
- Verify package provenance and registry integrity metadata. Where supported, require signed provenance and validate the expected package publisher.
- Use deterministic package-manager settings and integrity-checked caches in CI.
- Disable dependency lifecycle scripts where operationally feasible, or inspect all required lifecycle scripts before installation.
- Execute the scanner in a sandbox or isolated CI job with read-only repository access, a minimal environment, no unrelated secrets, and no unnecessary network or filesystem permissions.
- Avoid global installation in security-sensitive environments. If it is necessary, pin the exact version and document a controlled update and rollback procedure.
- Document the expected package identity, version, checksum or integrity value, and verification procedure directly in the skill.
- Pin the CLI to an exact reviewed version in all examples, such as
