T08 · Insecure Dependencies
- Location
SKILL.md:37- Finding
Unpinned On-Demand Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a reasonable debugging guide, but it needs review because some suggested JavaScript test commands can download and run unverified tools despite claiming no network access.
Review before installing. Use this skill only in trusted repositories or sandboxes, and prefer local-only test runner commands such as npm exec --no-install or direct node_modules binaries so the agent does not automatically download and run tools from a package registry.
SKILL.md:37Unpinned On-Demand Package Execution Through npx
The skill instructs use of npx jest --version to detect a test runner. npx may download and execute a package when it is not already installed locally, which means merely following the detection step can trigger unpinned code execution from a registry. In a debugging skill intended for arbitrary repositories, that creates unnecessary supply-chain and arbitrary execution risk.
The skill recommends npx vitest --version for auto-detection. As with other npx invocations, this can fetch and run an unpinned package if absent, exposing the agent to registry poisoning, typo-squatting, or unexpected package lifecycle script execution. Because this occurs during a preliminary detection step, the risk is broader than a deliberate trusted build action.
The same Technique 4 step also includes npx vitest run {test_file}. This presents unpinned package execution risk via npx, and because the skill is expressly for debugging potentially untrusted codebases, the operational context makes executing fetched tooling more dangerous than in a tightly controlled CI environment. An attacker could exploit the package resolution path or rely on absent local installs to trigger external code execution.
The same Technique 4 step also includes npx vitest run {test_file}. This presents unpinned package execution risk via npx, and because the skill is expressly for debugging potentially untrusted codebases, the operational context makes executing fetched tooling more dangerous than in a tightly controlled CI environment. An attacker could exploit the package resolution path or rely on absent local installs to trigger external code execution.
The full-suite verification step includes npx vitest run, again creating a path for unpinned package download and execution. In the context of an agent skill, this is a true security issue because the skill operationalizes a command that may execute external code not controlled by the repository owner or the user. The existing note about trusted repositories addresses repo code execution but not package-manager mediated tool retrieval.
The full-suite verification step includes npx vitest run, again creating a path for unpinned package download and execution. In the context of an agent skill, this is a true security issue because the skill operationalizes a command that may execute external code not controlled by the repository owner or the user. The existing note about trusted repositories addresses repo code execution but not package-manager mediated tool retrieval.
No suspicious patterns detected.