T08 · Insecure Dependencies
- Location
SKILL.md:166- Finding
Unpinned Global npm Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 166–172
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: MediumVulnerable Code
markdown ### Dependency: `docx` npm package Check if already installed, install if not: ```bash npm list -g docx 2>/dev/null | grep docx || npm install -g docxThis skill requires
docxv9+. No other runtime dependencies beyond Node.js.text The same unsafe installation behavior is also declared in `SKILL.md`, line 13, and documented in `README.md`, lines 47–52. ### Technical Analysis The Skill instructs the Agent to install the latest package named `docx` globally without pinning an exact audited version or verifying package integrity. The command therefore trusts whatever package release the configured npm registry resolves at execution time. This creates a supply-chain risk because a compromised registry account, malicious future release, registry substitution, or altered npm configuration could cause unreviewed code to be installed. npm packages may also contain lifecycle scripts that execute during installation with the permissions of the Agent process. The dependency check does not enforce the stated requirement for `docx` version 9 or later. `grep docx` merely checks for matching output, so an already installed incompatible version may satisfy the condition and suppress installation. Global installation unnecessarily modifies the shared Node.js environment. The installed package can consequently influence this Skill and other workloads that use the same global package location. ### Attack Path 1. An attacker compromises the relevant npm package release channel or controls the npm registry configured in the execution environment. 2. The `docx` package is absent when the Skill is invoked. 3. The Agent executes: ```bash npm install -g docx- npm retrieves an unconstrained package version from the configured registry.
- Malicious package code or li ...[truncated 949 chars]
- Remediation
View remediation
Remediation Suggestions
-
Define the dependency in a project-local
package.jsonusing an exact, reviewed version rather than a floating range:json { "dependencies": { "docx": "9.x.y" } }Replace
9.x.ywith the exact approved release. -
Commit a lockfile and use deterministic local installation:
bash npm ci --ignore-scripts -
Review whether the selected package requires lifecycle scripts. Keep
--ignore-scriptsenabled unless a specific audited script is essential. -
Import the project-local dependency rather than modifying or relying on the global Node.js environment.
-
Verify the installed version explicitly at runtime and fail closed when it is outside the supported range.
-
Use the official npm registry through a trusted configuration, retain lockfile integrity hashes, and incorporate dependency vulnerability and provenance checks into release review.
-
Remove the global installation instructions from
SKILL.md, its compatibility metadata, andREADME.mdso the unsafe path is not invoked through an alternate instruction.
-
