T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned npm Dependency Allows Supply-Chain Compromise
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 5
Vulnerability Type: Unpinned third-party npm dependency
Risk Level: MediumVulnerable Code
yaml metadata: {"clawdbot":{"emoji":"🗺️","requires":{"bins":["mcporter"],"env":["GOOGLE_MAPS_API_KEY"]},"primaryEnv":"GOOGLE_MAPS_API_KEY","install":[{"id":"node","kind":"node","package":"mcporter","bins":["mcporter"],"label":"Install mcporter (npm)"}]}}Technical Analysis
The installation metadata identifies
mcporteronly by its npm package name and does not specify an exact audited version or package integrity hash. Consequently, dependency resolution can retrieve a mutable future release from the configured npm registry.npm package installation may execute package lifecycle scripts. If the package, a maintainer account, or the package-distribution infrastructure is compromised, a malicious release could execute code during installation. This finding does not establish that the current
mcporterpackage is malicious; it identifies the absence of controls that bind installation to a reviewed artifact.Attack Path
- An attacker compromises the npm package, a maintainer account, or the dependency-distribution channel.
- The attacker publishes a malicious release under the expected
mcporterpackage name. - A user installs the Skill's required dependency using the unversioned installation declaration.
- npm resolves the mutable package reference to the malicious release.
- Malicious package code or lifecycle scripts execute with the privileges of the installation process.
- The payload may access files, environment variables, and network resources available to that process, potentially including
GOOGLE_MAPS_API_KEY.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the account running the dependency installation. The resulting scope is limited by that account's operating-system privileg ...[truncated 325 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
mcporterto an exact version that has been reviewed, rather than relying on an unversioned package reference. - Use a lockfile and verify npm integrity metadata so installation resolves to a known artifact.
- Configure an explicitly trusted npm registry and enforce registry allowlisting where supported.
- Review the pinned package's source, transitive dependencies, provenance, and lifecycle scripts before distribution.
- Disable npm lifecycle scripts during installation when they are not required, for example through an appropriate
ignore-scriptspolicy. - Run dependency installation with a non-privileged account in an isolated environment and expose only the minimum necessary credentials.
- Add automated dependency monitoring, provenance verification, and controlled upgrade review so version changes cannot silently introduce unreviewed code.
- Pin
