T08 · Insecure Dependencies
- Location
SKILL.md:145- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a legitimate Markdown linting helper, but users should pin the tooling version and review any repository-wide edits before committing.
Before installing or using this skill, prefer a pinned markdownlint-cli2 version or a project devDependency with a committed lockfile. Run bulk --fix and horizontal-rule cleanup commands only in a clean git working tree, preview affected files where possible, and review diffs before committing.
SKILL.md:145Unpinned Third-Party Package Execution Through npx
SKILL.md:126Destructive Batch Repair Uses Unsafe Filename Parsing
The skill repeatedly instructs users to invoke npx markdownlint-cli2 without pinning a specific package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk if a malicious or compromised release is published, especially because the command is presented as a routine prerequisite and validation step.
This instance again recommends npx markdownlint-cli2 with no version pin. In the context of an automation/setup skill, that means users may execute whatever version is current on the registry, exposing them to unexpected behavior or malicious upstream package changes.
The skill documents a batch-edit loop that rewrites files in place using awk and mv, but it does not give an explicit up-front warning that repository files will be modified and should be backed up or reviewed. In practice, users may paste and run the block verbatim, causing unintended content loss or large-scale edits, especially because the command targets multiple Markdown files automatically.
The --fix command uses unpinned npx, which combines automatic file modification with dynamic package resolution. If a compromised package version were fetched, it would run in a context where the user expects repository-wide edits, increasing the blast radius.
This verification command also executes an unpinned npx package from the registry. Although it appears read-only, it still runs arbitrary package code resolved at invocation time, so the main risk is supply-chain execution rather than linting behavior itself.
The monorepo-wide --fix example uses npx without version pinning, and it operates across many files. That makes a compromised upstream package especially risky because users are encouraged to run it broadly over a repository tree.
This monorepo check command still relies on unpinned remote package execution through npx. The skill context makes it more credible and likely to be copied verbatim, which increases practical exposure to registry compromise or malicious package updates.
The error-analysis pipeline invokes npx markdownlint-cli2 without fixing the package version. Because this is part of troubleshooting guidance, users may run it repeatedly over time, each time accepting whatever code the registry serves for the latest package version.
This file-statistics example also runs unpinned npx, preserving the same supply-chain execution risk. The surrounding shell pipeline does not itself introduce the issue; the primary problem is executing a mutable remote package identifier.
The validation step tells users to run an unpinned npx command after setup. This is a true issue because the skill normalizes executing code from the package registry without version control, creating a preventable supply-chain exposure.
The 'check existing repo' command continues the pattern of unpinned npx execution. In a security review, this is a real but moderate-severity vulnerability because it can lead to arbitrary code execution if the upstream package or dependency chain is compromised.
This auto-fix command is the highest-risk instance of the repeated npx pattern because it both executes unpinned remote package code and intentionally modifies repository contents. A malicious or compromised release could alter files, exfiltrate data, or run arbitrary shell behavior under the user's trust.
The skill's primary instructional content begins in Chinese and continues with Chinese-language usage guidance, but it does not indicate that language selection is optional or based on user preference. This can violate a language/locale policy when a skill effectively forces one language without opt-in.
No suspicious patterns detected.