T08 · Insecure Dependencies
- Location
SKILL.md:4- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 4 and 9–11
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumComplete Code Snippet:
yaml metadata: {"clawdbot":{"emoji":"💰","requires":{"bins":["ynab"],"env":["YNAB_API_KEY"]},"primaryEnv":"YNAB_API_KEY","install":[{"id":"node","kind":"node","package":"@stephendolan/ynab-cli","bins":["ynab"],"label":"Install ynab-cli (npm)"}]}}bash npm i -g @stephendolan/ynab-cliTechnical Analysis
The Skill directs users and the hosting framework to install
@stephendolan/ynab-cliwithout specifying a reviewed version or package integrity value. Consequently, installation resolves whichever release is current in the npm registry at installation time. The-goption installs the package globally, expanding its reach beyond the project directory.npm packages can execute lifecycle scripts during installation. If the package, a transitive dependency, the publisher account, or the upstream release process is compromised, attacker-controlled code could execute with the permissions of the user performing the installation. The installed CLI subsequently operates in an environment containing
YNAB_API_KEY, so a compromised dependency could access that credential when invoked.This is a supply-chain exposure rather than evidence that the currently published package is malicious.
Attack Path
- An attacker compromises the npm package publisher, release pipeline, package contents, or a transitive dependency.
- The attacker publishes a malicious release under the existing package name.
- A user or agent follows the documented command or automated installation metadata.
- Because no version or integrity value is pinned, npm retrieves the malicious current release.
- Malicious lifecycle code may execute during global installation with the installer's permissions.
- The globally installed
ynabexe ...[truncated 949 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specific version that has been reviewed, for example
@stephendolan/ynab-cli@<reviewed-version>, in both the installation metadata and documentation. - Record and verify package integrity using a lockfile or an equivalent cryptographic integrity mechanism.
- Prefer a project-local installation over
npm i -gto reduce system-wide impact and make dependency resolution reproducible. - Review the selected package version, its lifecycle scripts, and its transitive dependency tree before approval.
- Disable npm lifecycle scripts during installation when they are not required, such as with
--ignore-scripts, after confirming that the CLI remains functional. - Install and execute the CLI as an unprivileged user. Do not use elevated privileges for global npm installation.
- Limit exposure of
YNAB_API_KEYto the process that requires it, rotate the token if compromise is suspected, and avoid persisting it in shell history or plaintext configuration. - Establish an update process that reviews and tests each new version before changing the pinned dependency.
- Pin the dependency to a specific version that has been reviewed, for example
