T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned npm CLI Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26–35
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: Mediumbash # Install npx @opencodereview/cli scan ./src --sla L1 # With AI-powered deep scan (requires Ollama or API key) npx @opencodereview/cli scan ./src --sla L2 # Diff mode for CI/CD npx @opencodereview/cli scan ./src --diff --base origin/main --head HEAD # SARIF output for GitHub Actions npx @opencodereview/cli scan ./src --format sarif --output results.sarifTechnical Analysis
The documented commands execute
@opencodereview/clithroughnpxwithout specifying an exact package version or verifying package integrity. If the package is not already available locally,npxcan retrieve executable code from the npm registry at invocation time.Consequently, the code executed by these commands may differ from the code that existed when this Skill was reviewed. A compromised npm publisher account, malicious package release, registry compromise, or unauthorized ownership transfer could turn the documented command into a supply-chain execution vector.
The project contains no evidence that the current package is malicious. The vulnerability is the absence of version pinning and integrity controls around third-party executable retrieval.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another relevant distribution component.
- The attacker publishes a malicious version of
@opencodereview/cli. - A developer or automation system follows the documented unversioned
npxcommand. npxresolves and downloads the attacker-controlled package version.- Package lifecycle behavior or the invoked CLI executes with the permissions of the developer or automation account.
- The malicious dependency accesses repository contents, environment variables, credentials, or other resources available to that ...[truncated 532 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, reviewed version, such as
@opencodereview/cli@X.Y.Z. - Install dependencies through a committed lockfile using a deterministic installation command such as
npm ci. - Verify package integrity and provenance before approving version updates.
- Disable or restrict unnecessary package lifecycle scripts where operationally feasible.
- Run the scanner in a sandbox or isolated CI job with read-only repository access, minimal credentials, and restricted network access.
- Use controlled dependency-update tooling so that version changes receive explicit review and security testing.
- Pin the CLI to an exact, reviewed version, such as
