T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party CLI Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15 and 17
Vulnerability Type: Unpinned third-party dependencies from mutable external sources
Risk Level: MediumVulnerable Code
bash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The documented installation commands retrieve and install third-party code without pinning an audited version or verifying an integrity hash. The Go command explicitly selects
@latest, while the npm command implicitly resolves the latest package version available from the configured registry.The npm command also performs a global installation. Depending on the local npm configuration and user privileges, package lifecycle scripts or a malicious executable supplied by a compromised release could run with broad access to the user's files, environment variables, and development credentials.
This creates a supply-chain risk: the effective code installed when users follow the instructions can change after the skill has been reviewed. Exploitation would require compromise or malicious control of the package, repository, maintainer account, registry resolution, or release process. The audited file does not establish that the current upstream package is malicious.
Attack Path
- An attacker compromises the npm package, upstream repository, maintainer credentials, release pipeline, or another relevant distribution channel.
- The attacker publishes a malicious version as the latest release.
- A user or agent follows the installation instructions in
SKILL.md. - The unpinned command downloads the attacker-controlled release.
- Malicious installation logic, lifecycle scripts, build logic, or the installed CLI executes with the invoking user's privileges.
- The payload may access files and credentials available to that user or alter tools and project data within that user's permission b ...[truncated 504 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to a specific, reviewed release rather than resolving the latest version.
- Replace
@latestwith an immutable Go module version, preferably a reviewed release tag or commit. - Specify an exact npm package version and use a lockfile where installation occurs within a managed project.
- Avoid global npm installation where possible; use a project-local dependency or an isolated execution environment.
- Verify downloaded artifacts using trusted checksums, signatures, or package provenance attestations.
- Document the expected publisher, repository, version, and integrity value so users can validate package provenance.
- Review dependency updates before changing the pinned version and use automated supply-chain scanning.
- Perform document parsing in a sandbox with minimal filesystem access and without unrelated secrets in the environment.
