T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party CLI Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15-17
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Mediumbash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The documented installation commands retrieve third-party code without pinning it to an immutable, audited version. The npm command resolves the package version available under the registry's current default distribution tag, while the Go command explicitly retrieves
@latest.Consequently, the code installed by users can change after this skill has been reviewed. If the npm publisher account, package registry, source repository, release process, or another relevant supply-chain component is compromised, a modified release could execute attacker-controlled code during installation or when the CLI is invoked.
The global npm installation also broadens exposure by installing the executable into the user's global tool environment. This finding does not establish that the current dependency is malicious; it identifies an unsafe dependency acquisition practice.
Attack Path
- An attacker compromises the upstream package publisher, repository, release pipeline, or registry entry.
- The attacker publishes a malicious version under the npm default distribution tag or as the latest Go module version.
- A user follows the installation instructions in
SKILL.md. - The package manager downloads the unreviewed, mutable release.
- Malicious package installation logic or the installed CLI executes with the privileges of the invoking user.
- The attacker can access or modify resources available to that user, including data supplied to the conversion tool and environment variables exposed to the process.
Impact Assessment
Successful exploitation could provide arbitrary code execution with ...[truncated 436 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the npm package to a specifically reviewed version, for example
mineru-open-api@X.Y.Z. - Replace the Go
@latestselector with a specifically reviewed semantic version tag. - Verify downloaded artifacts using trusted checksums, signatures, provenance attestations, or an approved internal package mirror.
- Record the expected package owner, source repository, version, and integrity metadata so dependency provenance can be validated.
- Prefer a project-local or isolated installation over a global npm installation where operationally possible.
- Run the converter with least privilege and expose only the files, output directories, credentials, and network access required for conversion.
- Establish a controlled update process in which new dependency versions are reviewed and tested before changing the pinned version.
- Pin the npm package to a specifically reviewed version, for example
