T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned Third-Party npm Package Installed Globally
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-30 and 39-41
Vulnerability Type: Unpinned global dependency installation
Risk Level: MediumVulnerable Code
yaml install: - id: npm kind: npm package: voyageai-cli global: truebash npm install -g voyageai-cliTechnical Analysis
The Skill instructs users to install
voyageai-clifrom the npm registry without specifying an exact, reviewed version or an integrity constraint. Consequently, npm resolves the package to whichever version is current at installation time. The effective code executed by the Skill can therefore change after this repository has been audited.npm packages may execute package-controlled lifecycle scripts during installation. Because the package is installed globally, those scripts run with the permissions of the user invoking npm and can modify globally accessible command locations. This creates a supply-chain exposure if the package publisher account, npm package, release pipeline, or a future package version is compromised.
This finding does not establish that the current
voyageai-clipackage is malicious. The vulnerability is the unsafe dependency acquisition and installation practice, which places mutable third-party code outside the reviewed project into a trusted execution path.Attack Path
- An attacker compromises the npm publisher account, release process, or another component used to publish
voyageai-cli. - The attacker publishes a malicious version under the legitimate package name.
- A user follows the Skill instructions and executes
npm install -g voyageai-cliwithout a version constraint. - npm resolves and downloads the attacker-controlled release.
- Any malicious npm lifecycle script executes during installation with the invoking user's permissions.
- The installed
vaiexecutable can subsequently execute attacker logic when the user invokes ...[truncated 975 chars]
- An attacker compromises the npm publisher account, release process, or another component used to publish
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to an exact version that has been reviewed, for example:
yaml package: voyageai-cli@1.4.0and:
bash npm install -g voyageai-cli@1.4.0 -
Prefer a project-local dependency over a global installation so the package is isolated from global command paths:
bash npm install --save-exact voyageai-cli@1.4.0 npx vai --help -
Commit and enforce a lockfile with npm integrity hashes where the packaging format supports it. Use
npm cirather than unconstrained installation in automated environments. -
Verify package provenance, publisher identity, repository ownership, signatures or attestations, and the integrity of the selected release before recommending it.
-
Disable lifecycle scripts during installation when they are not required:
bash npm install --save-exact --ignore-scripts voyageai-cli@1.4.0If lifecycle scripts are required, review them before installation.
-
Perform installation as an unprivileged user. Do not use
sudoor an administrator account. -
Run the CLI in a restricted environment with only the minimum required credentials, filesystem access, and network permissions. MongoDB credentials should follow least privilege and should not grant unrelated administrative capabilities.
-
Establish a controlled update process in which newer dependency versions are reviewed and tested before the pinned version is changed.
-
