T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party CLI Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-17
Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Mediumbash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The installation instructions retrieve mutable dependency versions without pinning them to a previously audited release or commit. The npm command implicitly installs the package version currently associated with the registry's default distribution tag, while the Go command explicitly selects
@latest.Consequently, the code installed by these commands can change after the Skill has been reviewed. If the npm package, upstream repository, maintainer account, release pipeline, or package distribution channel is compromised, a malicious release could be delivered to users following these instructions. The global npm installation increases exposure because installation and package lifecycle code executes with the invoking user's permissions and places executables in a shared command path.
Attack Path
- An attacker compromises the upstream npm package, source repository, maintainer credentials, or release pipeline.
- The attacker publishes a malicious version and makes it the version resolved by the npm default tag or Go's
@latestselector. - A user follows the installation commands in
SKILL.md. - The package manager retrieves and installs the attacker-controlled release without validating a documented version, commit, checksum, or signature.
- Malicious installation hooks or CLI code executes with the user's privileges.
- The payload may access files available to that user, steal the configured
MINERU_TOKEN, inspect submitted presentations, alter generated OCR output, or execute additional local commands.
Impact Assessment
Successful exploitation could provide arbitrary co ...[truncated 544 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace mutable dependency references with an exact, reviewed version:
bash npm install mineru-open-api@EXACT_REVIEWED_VERSION go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@EXACT_REVIEWED_VERSION - Pin the Go installation to an immutable audited commit when reproducibility is required.
- Document expected artifact checksums or signature-verification procedures and verify downloaded releases before execution.
- Prefer a project-local npm installation with a lockfile over global installation, reducing shared command-path exposure and improving reproducibility.
- Review the package's lifecycle scripts, transitive dependencies, release provenance, and publisher identity before approving a version.
- Use a restricted, non-administrative account or isolated environment to install and run the CLI.
- Avoid exposing unrelated secrets to the process, scope the MinerU token to the minimum required permissions, and rotate it if dependency compromise is suspected.
- Establish a controlled update process in which newer releases are security-reviewed before the pinned version is changed.
- Replace mutable dependency references with an exact, reviewed version:
