T08 · Insecure Dependencies
- Location
SKILL.md:19- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 19
Vulnerability Type: Insecure third-party dependency installation
Risk Level: MediumVulnerable Code:
bash npm install -g todoist-ts-cli@^0.2.0Technical Analysis
The installation command uses the semver range
^0.2.0rather than an exact, audited version. It also provides no lockfile, integrity hash, package provenance verification, or lifecycle-script restriction. Consequently, the installed package content may change after the Skill has been reviewed.The global installation scope increases the impact because npm may execute package lifecycle scripts with the privileges of the installing user, and the package becomes available system-wide. The documentation states that the CLI is built on the official TypeScript SDK, but it does not establish that the CLI package itself is maintained or endorsed by Todoist.
Attack Path
- An attacker compromises the
todoist-ts-clipackage, its publisher account, or a dependency included by an allowed package release. - A malicious or compromised version satisfying
^0.2.0is published. - A user follows the documented global installation command.
- npm retrieves the compromised release and may execute its installation lifecycle scripts.
- Malicious code runs under the installing user's account and can access resources available to that account.
Impact Assessment
Successful exploitation could permit arbitrary local code execution with the privileges of the user running npm. Depending on those privileges, the attacker could access user files, environment variables, stored credentials, and Todoist authentication material. If installation is performed with elevated privileges, the potential scope may extend to system-wide resources.
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the package to an exact version that has been reviewed, rather than using a semver range.
- Record and verify package integrity and provenance before installation.
- Prefer a project-local dependency with a committed lockfile instead of a global installation.
- Review the package and its transitive dependency tree before recommending it.
- Disable npm lifecycle scripts during installation where compatible with the package's operation.
- Document that users should not run the installation with elevated privileges.
- Establish a controlled update process in which each new version is audited before the pin is changed.
