T08 · Insecure Dependencies
- Location
SKILL.md:357- Finding
Unpinned Third-Party npm Package Installation and Execution
- Content
View full analysis
npx lumail subscribers create --email user@example.com ``` ### Technical Analysis The skill directs users to globally install and execute the third-party `lumail` npm package without specifying an exact version, lockfile, or package integrity hash. The audited project contains only `SKILL.md`; it does not contain the referenced CLI or SDK source, dependency manifest, release workflow, or tests. Consequently, the code installed from npm cannot be verified against the reviewed artifact. An unpinned installation may retrieve a newer package release than the one intended when the skill was authored. npm package installation may also execute package lifecycle scripts, while subsequent `npx lumail` commands execute code supplied by the package. This creates a supply-chain trust boundary through which a compromised maintainer account, malicious package release, package replacement, or other registry compromise could introduce arbitrary code after this skill has been reviewed. The authentication command supplies a Lumail API token to the installed program. A malicious package could capture that token in addition to exercising the local permissions of the user running the command. ### Attack Path 1. An attacker compromises the referenced npm package, its publisher account, or its release process and publishes a malicious version. 2. A user follows the skill's instruction to run `npm install -g lumail` without an exact version or verified integrity digest. 3. npm retrieves the malicious release and may execute its lifecycle scripts with the privileges of the current user. 4. The user invokes `npx lumail auth set `, causing package-controlled code to receive the Lumail API token. ...[truncated 951 chars]- Remediation
View remediation
``` 2. Publish and verify the expected npm integrity digest or package provenance before installation. Use registry signatures and npm provenance attestations where available. 3. Provide a dependency manifest and lockfile that resolve the exact reviewed package version and transitive dependencies. 4. Link the package to a verifiable official source repository and release commit. Ensure the distributed npm artifact can be reproducibly matched to that source. 5. Include the CLI and SDK implementation in the audited skill artifact, or make the reviewed release artifact available for independent inspection. 6. Avoid global installation where possible. Run the tool in a restricted project environment, container, or dedicated low-privilege account. 7. Disable npm lifecycle scripts during installation where compatible: ```bash npm install --ignore-scripts lumail@ ``` 8. Issue a least-privilege Lumail API token with only the permissions required for the requested operation. Do not expose administrative credentials to the CLI. 9. Store the token using an operating-system credential manager or similarly protected secret store rather than relying solely on a plaintext configuration path. 10. Add an explicit confirmation step before destructive or externally visible operations such as deleting subscribers, sending campaigns, or sending transactional email. ]]>
