T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Global Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 15-17
Vulnerability Type: Unpinned third-party dependencies installed from mutable package registries
Risk Level: Mediumbash npm install -g mineru-open-api # or via Go (macOS/Linux): go install github.com/opendatalab/MinerU-Ecosystem/cli/mineru-open-api@latestTechnical Analysis
The installation instructions retrieve executable third-party code without pinning it to a reviewed, immutable version. The Go command explicitly selects
@latest, while the npm command implicitly resolves the registry's current release.The npm package is installed globally and may execute package lifecycle scripts during installation. Both installation methods therefore create a supply-chain trust boundary in which the code executed by users can change after this skill has been audited. A compromised publisher account, package registry, repository, or future release could cause these commands to install attacker-controlled code.
No evidence indicates that the currently referenced package is malicious. The vulnerability is the unsafe dependency acquisition practice and the inability to reproduce the reviewed dependency state.
Attack Path
- An attacker compromises the dependency publisher, source repository, release process, or package-registry account.
- The attacker publishes a malicious version of
mineru-open-apior modifies the release selected by@latest. - A user follows the documented installation commands.
- The package manager retrieves the attacker-controlled release rather than a previously reviewed version.
- Malicious npm lifecycle code may execute during installation, or malicious package code executes when the installed CLI is invoked.
- The payload operates with the permissions and environmental access of the invoking user.
Impact Assessment
Successful exploitation could allow arbitrary code execution under the invoking us ...[truncated 453 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin both installation methods to an explicitly reviewed version rather than relying on the current registry release or
@latest. - For npm, document an exact version, such as
npm install -g mineru-open-api@X.Y.Z, after verifying that release. - For Go, replace
@latestwith a reviewed semantic version or immutable commit reference. - Publish expected package integrity hashes or checksums and instruct users to verify downloaded artifacts.
- Prefer a project-local npm installation with a committed lockfile instead of a global installation where operationally feasible.
- Review npm lifecycle scripts and consider disabling them with
--ignore-scriptsif the package functions correctly without installation scripts. - Document the verified upstream repository and release provenance so users can detect dependency confusion or publisher changes.
- Periodically reassess pinned versions for security updates before deliberately advancing them.
- Warn users not to perform installation with elevated privileges unless it is strictly required.
- Pin both installation methods to an explicitly reviewed version rather than relying on the current registry release or
