T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Runtime Download and Execution of a Third-Party npm Package
- Content
View full analysis
``` The same runtime execution pattern is repeatedly recommended for wallet operations, paid HTTP requests, authentication, and service discovery. ### Technical Analysis The skill directs the agent to use `npx -y`, which can download and immediately execute the `@getalby/cli` npm package without interactive confirmation. Pinning the package to version `0.8.0` reduces version-drift risk, but it does not provide cryptographic integrity verification, a vendored dependency, or an independently reviewed lockfile. The package executes with the privileges of the agent process and is deliberately given access to wallet credentials through `NWC_URL`, command-line options, or files under `~/.alby-cli/`. A compromised npm release, registry response, package-maintainer account, transitive dependency, or local npm configuration could therefore run code in a security-sensitive context. This behavior is necessary only insofar as the skill relies entirely on the external Alby CLI. Automatic runtime installation is not the minimum privilege implementation: the CLI could instead be installed and verified by an administrator before the skill runs. There is no evidence in the audited files that the named package or pinned release is currently malicious. The issue is the unverified download-and-execute trust model. ### Attack Path 1. An attacker compromises the npm package, one of its dependencies, a maintainer account, the package-resolution path, or the configured npm registry. 2. The agent follows the skill and invokes `npx -y @getalby/cli@0.8.0`. 3. `npx` retrieves and executes package-controlled lifecycle or CLI code without requesting confirmation. 4. The code runs with the agent's operating-system permissions. 5. Because wallet ...[truncated 927 chars]- Remediation
View remediation
