T08 · Insecure Dependencies
- Location
SKILL.md:94- Finding
Unauthenticated npm Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 94-95
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
markdown - Prefer a preinstalled `agent-device` binary over on-demand package execution. - If install is required, pin an exact version (for example: `npx --yes agent-device@<exact-version> --help`).Technical Analysis
The documented fallback invokes
npxto retrieve and execute theagent-devicepackage from the configured npm registry. Although pinning an exact version reduces version drift, it does not independently authenticate the expected package contents or protect against registry compromise, maintainer-account compromise, malicious publication of the selected version, or registry configuration that resolves to an untrusted source.The
--yesoption suppresses the normal installation confirmation. Package lifecycle hooks and package runtime code may execute with the permissions of the user runningnpx. The command therefore crosses a supply-chain trust boundary without requiring integrity verification or provenance validation.Attack Path
- An attacker compromises the npm package, its publisher account, the configured registry, or the dependency resolution path.
- A user or agent follows the documented installation fallback.
npx --yesdownloads the selected package without an interactive confirmation step.- npm lifecycle code or the invoked package entry point executes locally.
- Malicious code operates with the invoking user's privileges and can access resources available in that environment.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user invoking
npx. Depending on the host environment, the affected scope could include project files, user-readable credentials and configuration, mobile automation artifacts under~/.agent-device, connected ...[truncated 293 chars]- Remediation
View remediation
Remediation Suggestions
- Prefer an already installed binary obtained through a documented, trusted distribution channel.
- Publish an explicit approved package version rather than leaving version selection to the operator.
- Require verification of the npm registry origin, package integrity hash, signatures, and available provenance attestations before execution.
- Avoid
--yesso unexpected installation or resolution behavior remains visible to the operator. - Install and inspect the package without executing lifecycle scripts where practical, then run it only after verification.
- Execute installation and first use in an isolated, least-privilege environment without production credentials or sensitive connected devices.
- Document a verified binary checksum or signed release process and provide a secure update procedure.
