T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Executable Dependencies Allow Supply-Chain Payload Substitution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15 and 23–29
Vulnerability Type: Unpinned third-party executable dependencies
Risk Level: MediumThe Skill metadata and installation instructions obtain the
mineru-open-apiexecutable without pinning it to an immutable, audited version.json "install":[ { "id":"npm", "kind":"node", "package":"mineru-open-api", "bins":["mineru-open-api"], "label":"Install via npm" }, { "id":"go", "kind":"go", "bins":["mineru-open-api"], "label":"Install via go install", "os":["darwin","linux"] } ]bash npm install -g mineru-open-apibash go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
Both documented installation mechanisms resolve mutable upstream artifacts at installation time. The npm command installs whichever package release currently satisfies the implicit latest-version selection, and the Go command explicitly requests
@latest. Neither mechanism pins an audited version, immutable source commit, checksum, or cryptographic signature.Consequently, the code executed by users can differ from the code that existed when this Skill was reviewed. An upstream package compromise, maintainer-account takeover, malicious release, or repository compromise could replace the expected CLI with attacker-controlled executable code. The global npm installation increases exposure because the resulting command is placed in the user's global executable environment.
This finding does not establish that the current upstream package is malicious. The vulnerability is the Skill's reliance on mutable executable dependencies without integrity controls.
Attack Path
- An attacker compromises the npm package, upstream repository, release pipeline, or a maintainer account associated with
mineru-open-api. - The attacker publish ...[truncated 1403 chars]
- An attacker compromises the npm package, upstream repository, release pipeline, or a maintainer account associated with
- Remediation
View remediation
Remediation Suggestions
- Pin the npm dependency to a specifically reviewed version, for example:
bash npm install -g mineru-open-api@<reviewed-version> - Pin the Go installation to a reviewed semantic version or immutable commit instead of
@latest:bash go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@<reviewed-version-or-commit> - Update the Skill metadata so its installation declaration also identifies the exact approved package version.
- Publish expected SHA-256 checksums or use verifiable release signatures, and require integrity verification before execution.
- Avoid automatic upgrade guidance that resolves the latest release without review. Establish a controlled process in which new versions are audited before the pin is updated.
- Where practical, install the CLI in an isolated environment rather than globally, and execute it with only the filesystem and network permissions required for document extraction.
- Disable or carefully review package lifecycle scripts during installation when supported by the deployment process.
- Pin the npm dependency to a specifically reviewed version, for example:
