T08 · Insecure Dependencies
- Location
skill.md:45- Finding
Unpinned Third-Party SDK Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
skill.md, lines 45-49
Vulnerability Type: Unpinned dependency installation
Risk Level: Mediumbash npm install @zyfai/sdk viemLatest version:
@zyfai/sdk@0.2.54Technical Analysis
The installation command does not pin either
@zyfai/sdkorviemto an exact version. Although the documentation states that the latest Zyfai SDK version is0.2.54, the command does not enforce that version. npm can therefore resolve a newer release at installation time.Because the project contains only
skill.md, no lockfile or integrity metadata is supplied to make dependency resolution reproducible. A future compromised, malicious, or incompatible package release could consequently be installed without any change to the reviewed skill.This is particularly sensitive because the documented SDK is given access to wallet providers, SIWE signatures, API keys, wallet addresses, and potentially private-key-backed
WalletClientobjects. Code executed by a compromised dependency would run with the privileges of the Node.js process and could access data available to that process.Attack Path
- An attacker compromises the npm account, publication pipeline, or package repository for one of the named dependencies.
- The attacker publishes a newer package version containing malicious runtime code or an npm lifecycle script.
- A user follows the documented unpinned
npm installcommand. - npm resolves and installs the attacker-controlled release.
- Malicious lifecycle code may execute during installation, or malicious SDK code may execute when imported or used.
- Depending on the host configuration, that code could inspect environment variables, API credentials, wallet configuration, accessible files, and signing interactions, then transmit collected data or manipulate transactions.
This is a conditional supply-chain exploitation path; the audit found no evidence ...[truncated 719 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin all direct dependencies to reviewed exact versions, for example:
bash npm install --save-exact @zyfai/sdk@0.2.54 viem@REVIEWED_EXACT_VERSION -
Provide and commit a reviewed
package-lock.json, then direct automated environments to use:bash npm ci -
Verify lockfile integrity and review dependency changes before upgrades. Use automated vulnerability and provenance checks, but do not permit unattended upgrades in wallet-signing environments.
-
Disable lifecycle scripts during installation where package functionality permits:
bash npm ci --ignore-scripts -
Run the SDK in a restricted process or container with minimal filesystem, network, and environment-variable access.
-
Keep raw private keys out of the SDK process. Prefer a KMS, hardware wallet, or policy-controlled remote signer that requires explicit authorization and constrains destination addresses, assets, chains, and transaction values.
-
Document the reviewed
viemversion alongside the SDK version and establish an explicit dependency-upgrade review procedure.
-
