T08 · Insecure Dependencies
- Location
SKILL.md:45- Finding
Unpinned Global Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 45
Vulnerability Type: Unsafe third-party dependency installation
Risk Level: MediumVulnerable Code Snippet
markdown - **cli_version 未安装**:可选;CLI `0.4.2` 已发布到 npm,先执行 `npm install -g wjx-cli@latest`,成功后再执行 `wjx skill install --force`,然后用 `wjx init --api-key <key>` 统一配置Technical Analysis
The optional setup instructions install
wjx-cli@latestglobally. Thelatesttag is mutable, so the installed package can differ from the version reviewed when this Skill was published. The instruction provides no exact version pin, package-integrity hash, publisher verification, lockfile, or lifecycle-script restriction.An npm package can run installation lifecycle scripts. A compromised maintainer account, malicious newly published release, or upstream package compromise could therefore result in arbitrary code execution under the privileges of the user running npm. Global installation also expands the impact by modifying the user's global Node.js tool environment.
This behavior is not the minimum privilege necessary for a documentation-only Skill. The same functionality could use an audited, exactly pinned version installed locally or in an isolated environment.
Attack Path
- An attacker compromises the
wjx-clipackage, its publisher account, or a relevant dependency. - The attacker publishes a malicious version and assigns or causes it to receive the
latestnpm tag. - A user follows the Skill instructions and runs
npm install -g wjx-cli@latest. - npm downloads the mutable package version and may execute its lifecycle scripts.
- Malicious code runs with the user's privileges and can access files, credentials, network resources, and globally installed tooling available to that account.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the invoking user. The resulting scope may include reading or modifying u ...[truncated 242 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
wjx-cli@latestwith an audited, exact version such as the explicitly referencedwjx-cli@0.4.2, after verifying that release. - Publish and verify the expected package integrity digest and official publisher or repository information.
- Prefer a project-local or isolated installation over a global installation.
- Use a lockfile where applicable and review transitive dependencies.
- Disable npm lifecycle scripts with
--ignore-scriptsif the package does not require them. - If lifecycle scripts are required, document and audit them before recommending installation.
- Advise users not to run package installation with administrator or root privileges.
- Replace
