T09 · Insecure Skill Coding Practices
- Location
src/index.ts:109- Finding
Unconfirmed Global npm Registry Modification
- Content
View full analysis
Vulnerability Details
File Location:
src/index.ts:109-115, invoked atsrc/index.ts:349-350
Vulnerability Type: Unapproved persistent environment configuration change
Risk Level: MediumVulnerable Code
typescript export async function setupNpmMirror(): Promise<boolean> { try { await execAsync('npm config set registry https://registry.npmmirror.com'); return true; } catch { return false; } }Invocation from the main handler:
typescript // 设置 npm 镜像源 await setupNpmMirror();Technical Analysis
A matching non-diagnostic message causes the handler to execute
npm config set registrywithout obtaining explicit user consent. Unless npm is configured otherwise, this command changes the user's npm configuration and affects package installations outside the current project.The previous registry value is not recorded, project-level scope is not specified, and no rollback mechanism is provided. The function also suppresses errors and returns a Boolean that the caller ignores. Consequently, the handler later reports that the registry was successfully configured even if the command failed.
Redirecting package resolution to a third-party mirror expands the software supply-chain trust boundary. Future npm commands may retrieve package metadata and artifacts through that mirror rather than the registry previously selected by the user or organization.
Attack Path
- A user submits a message containing one of the broad trigger phrases, such as
/win-fixor a matching natural-language phrase. - The handler runs dependency checks and then invokes
setupNpmMirror()without requesting confirmation. - npm's configured registry is changed to
https://registry.npmmirror.com. - Later npm installations, including installations unrelated to this Skill, use the changed registry.
- If the alternate registry or delivery path is compromised, manipulate ...[truncated 422 chars]
- A user submits a message containing one of the broad trigger phrases, such as
- Remediation
View remediation
Remediation Suggestions
- Obtain explicit user confirmation before changing any npm configuration.
- Prefer project-scoped configuration, such as writing a reviewed
.npmrcin the selected project, instead of modifying the user's global npm behavior. - Read and preserve the existing registry value before making a change.
- Provide a documented and automated rollback option.
- Check the result of
setupNpmMirror()and never report success when the operation failed. - Allow the user or administrator to supply an approved registry rather than hardcoding a third-party mirror.
- Clearly disclose the persistence and scope of the configuration change before execution.
