T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned External CLI Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14–17
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
markdown npx (requires Node.js):sh npx @usedada/cliTechnical Analysis
The skill instructs users and agents to execute
@usedada/clithroughnpxwithout specifying an exact package version. Depending on local npm behavior and cache state,npxcan retrieve the current package release from the npm registry and execute it with the invoking user's permissions.The audited project contains only
SKILL.mdandpackage.json; it does not contain the source code of@usedada/cli, a lockfile, an integrity hash, or another mechanism that binds this instruction to a reviewed artifact. The executable dependency is also distinct from the audited@usedada/pluginpackage. Consequently, the code that executes can change after this skill has been reviewed.No evidence establishes that the current external package is malicious. The risk arises from the mutable and unaudited supply-chain execution path.
Attack Path
- An attacker compromises the npm package, its publisher account, a maintainer's credentials, or another part of the package publication process.
- The attacker publishes a malicious or backdoored release under the legitimate
@usedada/clipackage name. - A user or agent follows the skill instruction and runs
npx @usedada/cli. npxresolves and downloads the mutable package release.- Package lifecycle scripts or CLI entry-point code execute locally with the permissions of the invoking account.
- The malicious code accesses or modifies resources available to that account before, during, or after presenting expected CLI behavior.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's operating-system privileges. The accessible scope could include project files, user-readable files, envi ...[truncated 301 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the command to a reviewed, immutable version, for example:
sh npx --yes @usedada/cli@x.y.z -
Review the source and publication provenance of that exact release before recommending it.
-
Publish SHA-256 checksums and, preferably, cryptographic signatures or attestations for prebuilt binaries, together with verification commands.
-
Link to an immutable source revision corresponding exactly to the pinned npm and binary releases.
-
Use package-lock or equivalent integrity metadata where the CLI is installed as part of a managed project.
-
Disable or avoid dependency lifecycle scripts where operationally practical.
-
Run the CLI with least privilege and avoid elevated execution.
-
Document where the Ed25519 private key is stored, its file permissions, backup expectations, and revocation or rotation procedures.
-
