T08 · Insecure Dependencies
- Location
SKILL.md:879- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:445,SKILL.md:486,SKILL.md:503,SKILL.md:879;references/profiling-tools-guide.md:9,references/profiling-tools-guide.md:59,references/profiling-tools-guide.md:75,references/profiling-tools-guide.md:128,references/profiling-tools-guide.md:156
Vulnerability Type: Supply-chain exposure through unpinned package installation and immediate package execution
Risk Level: MediumVulnerable Code
bash npm install why-is-node-running pip install py-spy pip install memory-profiler npx lighthouse https://example.com --output=html --output-path=report.htmlbash # references/profiling-tools-guide.md # py-spy pip install py-spy # Scalene pip install scalene # memray pip install memray # 0x npm install -g 0x # clinic.js npm install -g clinicTechnical Analysis
The instructions install packages without exact versions, hashes, lockfiles, or other integrity controls. The
npx lighthousecommand is particularly sensitive becausenpxcan retrieve and immediately execute a package when it is not already installed locally.Package installation and lifecycle scripts execute with the privileges of the invoking user. Global npm installation can also place executable files in shared command paths. Although the named packages are relevant to the Skill's declared debugging and profiling functionality, the installation method grants upstream package contents more trust than is strictly necessary.
This does not establish that any named package is malicious. The vulnerability is the absence of controls against compromised releases, unexpected future updates, registry manipulation, or dependency-chain compromise.
Attack Path
- An upstream package, one of its transitive dependencies, or a newly published package release is compromised.
- A user follows an unpinned
pip install,npm install -g, ornpxinstru ...[truncated 1127 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every recommended package to a reviewed exact version, such as
lighthouse@X.Y.Z,py-spy==X.Y.Z, or equivalent. - For npm tools, add the dependency to a project lockfile and invoke the locked local binary. Prefer
npx --no-install lighthouseafter a controlled installation. - Avoid global npm installation. Install profiling tools in a dedicated project or isolated tooling environment.
- For Python tools, use an isolated virtual environment or
pipxand require hash verification through a locked requirements file. - Enable package-manager integrity and provenance checks, audit transitive dependencies, and retrieve packages only from explicitly trusted registries.
- Document that package installation must not be performed with
sudoor from an administrator shell. - Periodically review and update pinned versions through a controlled dependency-update process.
- Pin every recommended package to a reviewed exact version, such as
