T08 · Insecure Dependencies
- Location
SKILL.md:38- Finding
Unpinned Global Installation of an Unauditable Third-Party CLI
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 38–41
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: MediumVulnerable Code
bash ## Install npm install -g @okx_ai/okx-trade-cli okx market ticker BTC-USDT # verifyAlthough the metadata at lines 14–18 identifies
@okx_ai/okx-trade-cli@1.3.7, the installation instructions actually executed by a user do not pin that version.Technical Analysis
The command installs the npm registry's current version rather than the declared and reviewed version
1.3.7. Consequently, the executable installed at runtime may differ from the dependency version represented in the Skill metadata.The dependency's implementation and a corresponding lockfile are not included in the audited project. Its install-time scripts, network destinations, profile handling, filesystem access, and runtime behavior therefore could not be verified in this audit. npm packages can run lifecycle scripts during installation, while later
okxinvocations execute package code with the invoking user's privileges.Global installation expands the exposure because it places an executable in a system- or user-wide command path. This behavior exceeds the minimum privilege needed to obtain public market data when a pinned, locally scoped dependency would suffice.
Attack Path
- An attacker compromises the npm publisher account, package release process, or an upstream dependency.
- The attacker publishes a malicious release under
@okx_ai/okx-trade-cli. - A user or Agent follows the documented unpinned command:
bash npm install -g @okx_ai/okx-trade-cli - npm resolves the latest release rather than the metadata-declared
1.3.7release. - Malicious package lifecycle code may execute during installation, or malicious runtime code executes when the documented
okxverification or market commands are invoked.
...[truncated 701 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the operational installation command to the same reviewed version declared in metadata:
bash npm install -g @okx_ai/okx-trade-cli@1.3.7 - Prefer a project-local, pinned installation over a global installation, then invoke the exact local binary.
- Commit a lockfile containing integrity hashes, or otherwise verify the package tarball against a trusted digest before installation.
- Verify package provenance, publisher identity, and signatures where supported.
- Disable npm lifecycle scripts with
--ignore-scriptsif the package does not require them; otherwise, separately audit every required lifecycle script. - Include or link to auditable source code that corresponds exactly to the pinned package release.
- Run the CLI as an unprivileged user and restrict filesystem and network access to what public market-data retrieval requires.
- Keep the frontmatter version and every installation example synchronized to prevent accidental upgrades to unreviewed code.
- Pin the operational installation command to the same reviewed version declared in metadata:
