T08 · Insecure Dependencies
- Location
SKILL.md:73- Finding
Unpinned Global Installation of a Third-Party CLI Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 73-77
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: Mediummarkdown ## Requirements - OpenCode CLI installed (`npm install -g opencode`) - Git repository for target project - PTY support enabled (automatic with `pty:true`)Technical Analysis
The documented installation command uses
npm install -g opencodewithout specifying an exact package version or integrity constraint. Consequently, users following these instructions receive whichever release the package registry currently resolves as the latest version rather than a previously reviewed and reproducible version.npm packages may execute lifecycle scripts during installation. Because the dependency is installed globally, those scripts execute with the privileges of the user running npm and the installed executable becomes available system-wide for that user. If the package, publisher account, or distribution channel is compromised, a malicious release could execute code during installation or when the CLI is later invoked against a project.
The audit found no evidence that the currently referenced package is malicious. The vulnerability is the unsafe, mutable dependency-installation practice and its associated supply-chain exposure.
Attack Path
- An attacker compromises the package publisher, npm account, package distribution channel, or a future package release.
- The attacker publishes a malicious version under the referenced
opencodepackage name. - A user follows the Skill documentation and executes
npm install -g opencode. - npm resolves and downloads the attacker-controlled latest release because no exact version or integrity value is specified.
- Malicious package lifecycle scripts can execute during installation, or malicious behavior can execute when
opencode runis invoked. - The malicious process can access resour ...[truncated 812 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin OpenCode to an exact, reviewed version rather than resolving the mutable latest release.
- Verify and document the package's official name, publisher identity, registry, and release provenance.
- Prefer a project-local development dependency governed by a committed lockfile instead of a global installation.
- Enforce package integrity verification and use trusted registry configuration.
- Review package contents and lifecycle scripts before approving version upgrades.
- Run the CLI with least privilege and restrict its access to credentials, sensitive environment variables, unrelated directories, and unnecessary network resources.
- Execute it in an isolated development environment or sandbox where feasible.
- Require users to inspect generated changes and repository diffs before committing or deploying them.
