T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party npm Dependencies Create Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:25references/quickstart.md:6-8references/quickstart.md:44
Vulnerability Type: Third-party dependencies are installed without exact version or integrity constraints
Risk Level: LowAffected code in
SKILL.md:25:bash npm install @weiyi/wand-uiAffected code in
references/quickstart.md:6-8:bash npm install @weiyi/wand-ui # or yarn add @weiyi/wand-uiAffected code in
references/quickstart.md:44:bash npm install babel-plugin-component -DTechnical Analysis
These installation commands do not specify reviewed dependency versions or integrity hashes. Consequently, npm or Yarn resolves a mutable package version from the configured registry at installation time. The installed code can therefore differ from the version that existed when the Skill was audited.
Package installation may execute dependency lifecycle scripts, including
preinstall,install, andpostinstall. If the named package, one of its transitive dependencies, or the configured package registry is compromised, malicious code could execute during installation. Even without malicious activity, an incompatible future release could introduce security regressions into generated projects.The audit did not identify evidence that the named packages are currently malicious. The issue is the absence of controls that make dependency resolution reproducible and restrict exposure to future supply-chain compromise.
Attack Path
- An attacker compromises a referenced package, a transitive dependency, a maintainer account, or the package registry used by the developer.
- The attacker publishes a malicious version containing a lifecycle script or malicious runtime code.
- A developer follows the Skill documentation and runs an unpinned
npm installoryarn addcommand. - The package manager resolves the attacker-controlled r ...[truncated 1022 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace unconstrained installation examples with exact, reviewed versions, for example:
bash npm install --save-exact @weiyi/wand-ui@<reviewed-version> npm install --save-dev --save-exact babel-plugin-component@<reviewed-version> - Generate and commit
package-lock.jsonor the applicable Yarn lockfile so transitive dependencies and integrity hashes are reproducible. - In automated environments, use
npm ciagainst the committed lockfile rather than dynamically resolving dependencies. - Review package provenance, maintainers, release history, and registry source before selecting the pinned versions.
- Configure an approved registry and lock down package-manager configuration to reduce dependency-confusion and registry-substitution risks.
- Where package behavior permits, install with lifecycle scripts disabled, such as
npm ci --ignore-scripts, and explicitly run only reviewed build steps afterward. - Add dependency vulnerability and integrity scanning to CI, and update pinned versions through a controlled review process.
- Document the exact versions that were tested with this Skill and update them only after source and release verification.
- Replace unconstrained installation examples with exact, reviewed versions, for example:
