T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Unpinned npm Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 6
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code Snippet:
markdown `npm i draco3d` (WASM codec) | CDN: `gstatic.com/draco/versioned/decoders/1.5.7/`Technical Analysis
The installation instruction does not specify an exact version of the
draco3dnpm package. Consequently, users following this instruction will install whichever package version currently satisfies npm's default resolution behavior. The resolved registry artifact can change after the skill has been reviewed.This creates a supply-chain risk because a future malicious or compromised package release could introduce harmful runtime code or npm lifecycle scripts. Such scripts may execute during installation with the permissions of the user running npm. Although the referenced CDN decoder is version-pinned to
1.5.7, that pin does not protect the separate npm installation command.No evidence indicates that the currently documented package is malicious. The vulnerability is the unsafe, mutable dependency-resolution practice.
Attack Path
- An attacker compromises the
draco3dpublishing account, npm distribution process, or a future package release. - The attacker publishes a modified package version containing malicious runtime code or an installation lifecycle script.
- A user follows the documented
npm i draco3dinstruction without an exact version or reviewed lockfile. - npm resolves and downloads the attacker-controlled release.
- Malicious lifecycle code may execute during installation, or malicious package code may execute when the application imports and uses the dependency.
Impact Assessment
Successful exploitation could execute code with the privileges of the user or automation account performing installation or running the resulting application. Depending on that account's access, the attacker could read o ...[truncated 332 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace the unversioned command with an exact, reviewed release, for example:
npm install --save-exact draco3d@<reviewed-version>. - Commit a generated lockfile containing registry URLs and integrity hashes.
- Use
npm ciin CI/CD and production build environments to enforce lockfile resolution. - Review package provenance, maintainers, release history, and published artifacts before upgrading.
- Perform dependency updates through a controlled review process with security scanning and testing.
- Where package lifecycle scripts are unnecessary, install with
--ignore-scriptsor enforce an equivalent package-manager policy. - Pin and verify all remotely hosted WASM and JavaScript assets; consider self-hosting reviewed artifacts and applying Subresource Integrity where supported.
- Replace the unversioned command with an exact, reviewed release, for example:
