T08 · Insecure Dependencies
- Location
SKILL.md:72- Finding
Unpinned Global Installation and Execution of an Unaudited Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 72-79
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: MediumVulnerable Code Snippet
markdown ## Prerequisites The `agent-media` CLI must be installed and authenticated: ```bash npm install -g agent-media-cli agent-media logintext ### Technical Analysis The skill instructs users to install `agent-media-cli` globally from the npm registry without specifying an exact version or verifying its integrity or provenance. The dependency's source code is not included in the audited project, so its installation scripts and runtime behavior cannot be verified from the available artifact. An npm package can execute lifecycle scripts during installation. A global installation also places an executable on the system path and runs installation behavior with the permissions of the invoking user. Because no version or integrity digest is pinned, the effective code installed by this command can change after the skill has been reviewed. This is a supply-chain security weakness rather than evidence that the referenced package is presently malicious. ### Attack Path 1. An attacker compromises the npm publisher account, package release process, or another component of the package's supply chain. 2. The attacker publishes a malicious or backdoored version under the existing `agent-media-cli` package name. 3. A user follows the skill instructions and runs `npm install -g agent-media-cli`. 4. npm retrieves the current package release without enforcing an audited version or integrity value. 5. Malicious package lifecycle scripts can execute during installation, or malicious behavior can run when the user invokes `agent-media login` or subsequent media commands. 6. The package operates with the invoking user's privileges and can potentially access files, environment variables, authentication material, and data supplied to the CLI. ### Impact Assessment Suc ...[truncated 817 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to an explicitly reviewed version instead of installing the latest release implicitly:
bash npm install --global agent-media-cli@<reviewed-version> -
Record and verify the expected package integrity digest and publisher provenance before installation. Use npm provenance information and require releases produced through a trusted, auditable build process.
-
Avoid global installation where possible. Install the dependency in a dedicated project with a committed lockfile, or run it in an isolated container or restricted environment.
-
Audit the exact package version, including its transitive dependencies and npm lifecycle scripts, before recommending it.
-
Disable npm lifecycle scripts during installation when they are not required:
bash npm install --ignore-scripts agent-media-cli@<reviewed-version>If lifecycle scripts are necessary, review them explicitly before allowing execution.
-
Execute the CLI under a least-privileged account with access limited to the media files required for the task. Do not expose unrelated credential directories, SSH keys, cloud credentials, or sensitive environment variables.
-
Clearly disclose that local screenshots, voice samples, face photographs, and other media may be uploaded to an external service. Obtain user authorization before transmitting such data and document the destination, retention policy, and deletion process.
-
