T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Third-Party npm Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 20–21
Vulnerability Type: Unpinned and immediately executable third-party dependency
Risk Level: MediumComplete Code Snippet:
markdown - Global install: `npm install -g frigatebird` - Local use: `npx frigatebird <command>`Technical Analysis
The skill instructs users or agents to install and execute the
frigatebirdnpm package without specifying a reviewed version, integrity hash, lockfile, or verified source repository. Both commands therefore resolve mutable package content from the configured npm registry.In particular,
npx frigatebird <command>may download and immediately execute the package. npm installation can also run package lifecycle scripts. Consequently, a compromised account, malicious replacement release, dependency compromise, registry substitution, or unexpectedly changed package version could cause attacker-controlled code to run without any corresponding change to the reviewed skill file.The package is intended to interact with authenticated X sessions and accepts authentication tokens, cookies, cookie sources, and browser-profile options. Although the reviewed file contains no evidence that the current package is malicious, the unpinned execution guidance creates a supply-chain exposure with elevated consequences.
Attack Path
- An attacker compromises the npm package, one of its transitive dependencies, its publisher account, or the registry path used by the victim.
- The attacker publishes a malicious version under the package name resolved by the unpinned commands.
- A user or agent follows the skill instructions and runs
npm install -g frigatebirdornpx frigatebird <command>. - npm retrieves the attacker-controlled release because no trusted version or integrity value is required.
- Malicious package code or lifecycle scripts execute with the permissions of the invoking ac ...[truncated 962 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the package to a specifically reviewed version, for example
frigatebird@X.Y.Z, instead of resolving the latest release. - Prefer a project-local installation governed by a committed lockfile rather than a mutable global installation.
- Verify package provenance, publisher identity, repository ownership, release signatures or attestations, and npm integrity metadata before use.
- Use deterministic installation such as
npm ciwith a reviewed lockfile where the surrounding project structure permits it. - Avoid direct
npxexecution of an unpinned package. Ifnpxremains necessary, specify the exact reviewed version and configure it to avoid silently resolving unexpected packages. - Disable npm lifecycle scripts during installation where compatible with the package, or independently review every required lifecycle script before permitting execution.
- Run the CLI with least privilege in an isolated environment and expose only the specific browser profile, cookies, and credentials required for the requested operation.
- Document the authoritative source repository and a package verification procedure so users can validate that the installed artifact corresponds to the reviewed implementation.
- Pin the package to a specifically reviewed version, for example
