T08 · Insecure Dependencies
- Location
SKILL.md:105- Finding
Unpinned npm CLI Execution Creates a Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:105-106; duplicated inREADME.md:48-49
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumVulnerable code in
SKILL.md:bash npx skills add multi-thread-dialogue # or npx skills add multi-thread-dialogue -gDuplicated vulnerable code in
README.md:bash npx skills add multi-thread-dialogue # or globally npx skills add multi-thread-dialogue -gTechnical Analysis
The installation instructions invoke the
skillsnpm CLI throughnpxwithout specifying a package version or verifying package integrity. If the package is not already available locally,npxcan retrieve and execute the currently published package from the configured npm registry.Consequently, the code executed during installation is not fixed to the version reviewed in this audit. A compromised maintainer account, malicious replacement release, registry configuration attack, or other supply-chain compromise could cause a different package payload to run. The documentation also does not provide a checksum, lockfile, verified publisher identity, or other mechanism that binds the npm package to the declared GitHub project.
The global installation variant (
-g) increases the scope because it can place package files or commands in globally configured npm locations. The exact permissions depend on the user's npm and operating-system configuration.Attack Path
- An attacker compromises the publication channel or maintainer account for the unpinned
skillsnpm package, or causes the victim's configured registry to resolve the package to an attacker-controlled release. - The attacker publishes a malicious package version or modifies executable installation behavior.
- A user follows the documented command:
bash npx skills add multi-thread-dialogue npxresolves and downloads the current package version rather th ...[truncated 1122 chars]
- An attacker compromises the publication channel or maintainer account for the unpinned
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI package to a specifically reviewed version:
bash npx --yes skills@<audited-version> add multi-thread-dialogue - Verify the exact package name, registry namespace, publisher identity, and provenance before recommending it.
- Publish and document an integrity checksum or signed provenance record that allows users to verify the retrieved artifact.
- Prefer a lockfile-backed local development dependency over ad hoc retrieval and execution through an unpinned
npxcommand. - Avoid recommending global installation by default. If global installation is necessary, explain the affected directories and explicitly state that the command must not be run with elevated privileges.
- Provide a non-executing manual installation method, such as downloading a versioned release archive, verifying its checksum or signature, inspecting its contents, and then copying the required files.
- Keep
SKILL.mdandREADME.mdsynchronized so both documents use the same hardened installation procedure.
- Pin the CLI package to a specifically reviewed version:
