T08 · Insecure Dependencies
- Location
SKILL.md:45- Finding
Unpinned Remote npm Package Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 45–51
Vulnerability Type: Unpinned third-party dependency executed throughnpx
Risk Level: MediumComplete Code Snippet:
bash CAREERMAX_API_KEY="cmx_live_..." npx -y --package @careermax/agent-toolkit@latest careermax-mcpbash npx -y --package @careermax/agent-toolkit@latest careermax cover-letter generate --job-id <id>Technical Analysis
The documented commands use
npx -yto download and execute the external@careermax/agent-toolkitnpm package without interactive confirmation. The MCP command explicitly selects the mutable@latesttag, while the CLI command also omits an exact version. Consequently, the code executed by future invocations can differ from the code available when this skill was reviewed.The project contains no lockfile, integrity hash, pinned package version, or local implementation that would allow the executed dependency to be reproducibly verified. In the MCP command, the downloaded process also receives
CAREERMAX_API_KEYthrough its environment. The package name and scope are consistent with the declared CareerMax integration, so the reviewed evidence does not establish malicious intent, dependency confusion, or typosquatting. The vulnerability is the unsafe, unpinned supply-chain execution pattern.Attack Path
- An attacker compromises the npm package, its maintainer account, publishing credentials, or release process.
- The attacker publishes a malicious release and makes it the version resolved by
@latest, or otherwise the default version selected by the unversioned command. - A user invokes one of the commands documented in
SKILL.md. npx -ydownloads and executes the attacker-controlled package without requesting confirmation.- The package runs with the invoking user's operating-system permissions.
- During MCP execution, the malicious process can access `CAREERMAX ...[truncated 817 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestand the unversioned package reference with an exact, reviewed version, for example@careermax/agent-toolkit@X.Y.Z. - Use a committed lockfile and reproducible installation workflow where the deployment model permits it.
- Verify npm package provenance, publisher identity, signatures or attestations, and registry integrity before approving each version.
- Record and validate the expected package integrity hash when supported by the installation workflow.
- Do not update the pinned version automatically. Require security review and testing before each dependency upgrade.
- Run the MCP server and CLI in a sandbox or container with minimal filesystem access, restricted network destinations, and no unnecessary operating-system privileges.
- Provide
CAREERMAX_API_KEYonly to a verified process, use a narrowly scoped credential if supported, and establish rotation and revocation procedures. - Avoid
npx -yfor security-sensitive execution when an installed, reviewed, and integrity-verified binary can be used instead.
- Replace
