T08 · Insecure Dependencies
- Location
SKILL.md:62- Finding
Unpinned External Source and Unsafe Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 62 and 69-74
Vulnerability Type: Unpinned third-party source and dependency supply-chain exposure
Risk Level: MediumVulnerable Code
markdown 1. Clone [telegram-for-ai-agents](https://github.com/chihoai/telegram-for-ai-agents).bash npm install cp .env.example .env npm run dev -- auth npm run mcpTechnical Analysis
The instructions tell users to clone an external repository without selecting a reviewed commit hash or signed release. They then direct users to install its npm dependencies and execute its npm scripts.
Because the repository's mutable default branch and dependency graph can change after this skill is reviewed, the code ultimately executed is not fixed by the audited artifact. In addition,
npm installcan execute package lifecycle scripts. Consequently, a compromised upstream repository, malicious dependency release, dependency takeover, or altered transitive package could result in arbitrary local code execution.The external repository, its lockfile, npm packages, and runtime implementation were not included in the supplied project, so their integrity could not be verified during this audit.
Attack Path
- An attacker compromises the upstream GitHub repository, a direct npm dependency, or a transitive dependency.
- The attacker adds malicious code to the mutable default branch, an installed package, or a package lifecycle script.
- A user follows the skill instructions and clones the current upstream revision without verifying a commit or signed release.
- The user runs
npm install, which downloads unreviewed dependencies and may execute lifecycle scripts. - The user runs
npm run dev -- authandnpm run mcp, executing the downloaded application. - The malicious code executes with the operating-system privileges of the invoking user and may access credentials or session data available t ...[truncated 799 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the external repository to a reviewed commit hash or cryptographically signed release instead of using its mutable default branch.
- Document the expected commit identifier and provide a verification command before installation or execution.
- Commit and review a dependency lockfile, then use
npm cirather thannpm installto enforce the locked dependency graph. - Apply lockfile and package integrity verification in deployment or setup procedures.
- Use
npm ci --ignore-scriptswhere lifecycle scripts are unnecessary. If scripts are required, identify and audit each required script before enabling it. - Regularly scan direct and transitive dependencies for known vulnerabilities, package takeovers, and unexpected source changes.
- Run the service under a dedicated, least-privileged operating-system account or inside a restricted container.
- Store Telegram and database credentials with restrictive permissions and expose them only to the required process.
- Prefer a dedicated Telegram account with limited chat membership instead of a personal account to reduce the consequences of compromise.
