T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 8–10 and 29–31
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumVulnerable Code
yaml install: - kind: node package: agt-tunnel bins: [agt]bash npm install -g agt-tunnelTechnical Analysis
The skill directs the environment to install the mutable latest release of the third-party
agt-tunnelnpm package without specifying an audited version or integrity hash. The global installation option (-g) places the package executable into the user's global npm environment.Because the dependency's source code is not included in the audited project, its installation scripts and runtime behavior cannot be verified from this artifact. A compromised package release, maintainer account, or upstream distribution channel could cause a future installation to execute code different from the version originally reviewed. npm lifecycle scripts may execute during installation under the privileges of the user running npm.
Attack Path
- An attacker compromises the
agt-tunnelnpm package, its maintainer account, or its publication pipeline. - The attacker publishes a malicious release under the existing package name.
- An agent follows
SKILL.mdand executesnpm install -g agt-tunnel. - npm resolves the unpinned dependency to the attacker-controlled release.
- Malicious npm lifecycle code executes during installation, or the installed
agtexecutable runs malicious logic when invoked. - The payload acts with the permissions of the installing user and may affect the user's global npm environment.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation. Depending on those privileges and the host configuration, the malicious package could access user-readable files and credentials, make network requests, alter the global npm environmen ...[truncated 177 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
agt-tunnelto a specific version that has undergone security review rather than installing the mutable latest release. - Verify the package using a lockfile and registry-provided integrity metadata.
- Prefer a project-local installation over
npm install -gto limit changes to the user's global tool environment. - Review the package source, transitive dependencies, and npm lifecycle scripts before authorizing installation.
- Disable lifecycle scripts with
--ignore-scriptswhere compatible with the package. - Execute the CLI in a sandbox or restricted environment with minimum filesystem, credential, and network access.
- Establish an update-review process so package upgrades are explicitly assessed before the pinned version is changed.
- Pin
