T08 · Insecure Dependencies
- Location
SKILL.md:159- Finding
Unpinned Global Dependency and Mutable Remote Setup Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 159–166
Vulnerability Type: Supply-chain exposure through an unpinned global package installation and mutable remote instructions
Risk Level: Mediummarkdown - **Twitter fetch failed?** Ensure `undici` is installed: `npm install -g undici`. Configure proxy: `agent-reach configure proxy URL`. ## Setting Up a Channel ("帮我配 XXX") If a channel needs setup (cookies, Docker, etc.), fetch the install guide: https://raw.githubusercontent.com/Panniantong/agent-reach/main/docs/install.md User only provides cookies. Everything else is your job.Technical Analysis
The troubleshooting instructions install the latest available version of
undiciglobally without a fixed version, lockfile, or integrity verification. Package installation can execute package lifecycle logic and places files in a globally accessible tool location. Consequently, the behavior installed at execution time is not necessarily the behavior that existed when this Skill was reviewed.The setup workflow also directs the agent to retrieve instructions from the mutable
mainbranch of an external GitHub repository and broadly instructs it to perform all setup work. The retrieved document is not part of this audited project, is not pinned to a reviewed commit, and can change independently. Although the audited file does not itself explicitly execute a downloaded payload, following subsequently modified setup instructions could cause the agent to install or run unaudited components.Attack Path
- An attacker compromises the relevant npm package publication path, dependency resolution path, GitHub repository, or maintainer account.
- The attacker publishes a malicious package release or modifies
docs/install.mdon the mutablemainbranch to include unsafe installation or execution steps. - A user encounters a Twitter-channel failure or requests configuration of a supported cha ...[truncated 983 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
undicito a specifically reviewed version rather than installing the latest release. - Use a project-local dependency manifest and lockfile instead of a global npm installation.
- Verify dependency integrity with trusted registry metadata and lockfile integrity hashes.
- Disable or strictly control package lifecycle scripts where they are not required.
- Pin the installation guide to a reviewed commit hash instead of the mutable
mainbranch. - Vendor reviewed setup instructions into the Skill package so that audited behavior cannot change remotely.
- Require explicit user confirmation before installing software, starting containers, importing cookies, or executing commands obtained from external documentation.
- Restrict setup operations to a sandbox or least-privileged environment and avoid exposing unrelated credentials or user files.
- Re-review and update pinned dependencies and documentation through a controlled release process.
- Pin
