T08 · Insecure Dependencies
- Location
SKILL.md:21- Finding
Mutable Third-Party Package Is Downloaded and Executed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 21; representative command invocations at lines 84–85, 91–93, 99, 105, 115–116, 122–123, 134–145, 151, 160–161, 200–204, and 210–211
Vulnerability Type: Runtime execution of an unpinned third-party dependency
Risk Level: MediumVulnerable Code
markdown Automate HarmonyOS NEXT devices using `npx -y @midscene/harmony@1`.Representative executable commands include:
bash npx -y @midscene/harmony@1 connect npx -y @midscene/harmony@1 connect --deviceId 0123456789ABCDEFbash npx -y @midscene/harmony@1 runhdcshell --command "hidumper -s RenderService -a screen"bash npx -y @midscene/harmony@1 act --prompt "type hello world in the search field and press Enter" npx -y @midscene/harmony@1 act --prompt "long press the message bubble and tap Delete in the popup menu"Technical Analysis
The Skill instructs the agent to execute
@midscene/harmonythroughnpx -y. The-yoption suppresses the package-installation confirmation, while the version selector@1permits npm to resolve a changing release within major version 1 rather than an exact, previously audited version.If the package is unavailable locally,
npxcan retrieve it from the configured npm registry and execute its CLI code. Package lifecycle scripts may also execute during installation, depending on npm configuration. Consequently, the code that runs can change without any corresponding modification to this repository orSKILL.md.This creates a supply-chain trust boundary: security depends on the package publisher, publisher credentials, registry configuration, package dependencies, and whichever compatible version is selected at execution time. The repository contains no lockfile or integrity metadata that would ensure the executed artifact is identical to an audited release.
Attack Path
- An attacker compromises the package publisher, ...[truncated 1416 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace the mutable major-version selector with an exact, reviewed package version, such as
@midscene/harmony@1.x.y. - Prefer installing dependencies through a committed lockfile containing resolved versions and integrity hashes rather than downloading them during every Skill execution.
- Use
npm ciin a controlled build or preparation phase, then invoke the locally installed binary withnpx --no-installor an equivalent package-manager command. - Review the package and its transitive dependency tree before approving upgrades. Apply dependency updates through an explicit review process.
- Disable lifecycle scripts during installation where compatible with the package, or inspect and explicitly approve required scripts.
- Configure npm to use a trusted registry and protect registry configuration from user-controlled or project-controlled overrides.
- Run device automation in a sandbox or dedicated low-privilege account with narrowly scoped filesystem and network access.
- Provide only task-specific credentials to the process, rotate exposed credentials, and avoid placing unrelated secrets in its environment.
- Limit HDC access to the intended device and disconnect the device when automation is complete.
- Document that screenshots and other visual data may be sent to the configured external model provider, and avoid exposing sensitive on-screen information unless explicitly required.
- Replace the mutable major-version selector with an exact, reviewed package version, such as
