T08 · Insecure Dependencies
- Location
scripts/init-slidev.sh:19- Finding
Unpinned npm dependencies are downloaded and executed
- Content
View full analysis
/dev/null 2>&1; then echo "📥 安装 Slidev..." npm install @slidev/cli > /dev/null 2>&1 fi ``` `SKILL.md:99-100`: ```bash npm install slidev-theme-xxx ``` `SKILL.md:327-335`: ```bash npx slidev export slides.md npx slidev export slides.md --format pptx npx slidev export slides.md --format png ``` `SKILL.md:357-389`: ```bash npx --yes @slidev/cli --version 2>/dev/null test -d node_modules && npm ls @slidev/cli 2>/dev/null cd 项目目录 npm install @slidev/cli npm install -g @slidev/cli npm init slidev npm install -D playwright-chromium ``` `SKILL.md:394-405`: ```bash echo '{"name":"ppt","private":true}' > package.json npm install @slidev/cli npm install -D playwright-chromium npx @slidev/cli slides.md --remote ``` `references/quickref.md:13-23`: ```bash npm init slidev npx @slidev/cli slides.md npx @slidev/cli slides.md --remote npx @slidev/cli export slides.md npx @slidev/cli export slides.md --format pptx ``` ### Technical Analysis The project installs and executes npm packages without specifying reviewed, exact versions or enforcing a lockfile. Commands such as `npm install @slidev/cli`, `npm init slidev`, and `npx @slidev/cli` resolve packages from the configured npm registry at execution time. Consequently, the code executed during a future skill invocation can differ from the code that was available when the skill itself was audited. npm installations may execute package lifecycle scripts with the privileges of the user running the skill. The generic instruction to install `slidev-theme-xxx` also permits selection of arbitrary community packages without an ...[truncated 2743 chars]- Remediation
View remediation
npm install --save-dev --save-exact playwright-chromium@ ``` 2. Commit a reviewed `package-lock.json` and use deterministic installation: ```bash npm ci ``` 3. Configure CI to reject lockfile drift and verify that `package.json` and `package-lock.json` remain synchronized. 4. Replace all ambiguous `npx slidev` examples with the reviewed `@slidev/cli` package. Prefer local binaries installed from the lockfile: ```bash npm exec --offline -- @slidev/cli slides.md ``` 5. Avoid `npm init slidev` and unpinned `npx` execution in automated workflows. If temporary execution is unavoidable, specify an exact reviewed version and require explicit user approval before downloading it. 6. Maintain an allowlist of reviewed Slidev themes with exact versions. Do not automatically install arbitrary package names supplied through presentation content or untrusted user material. 7. Review dependency lifecycle scripts and package provenance before installation. Where compatible with the required packages, consider initially installing with lifecycle scripts disabled: ```bash npm ci --ignore-scripts ``` Only run specifically required and reviewed setup steps afterward. 8. Remove the global installation recommendation because global packages increase the affected scope and are harder to reproduce or audit. 9. Require explicit user confirmation before enabling `--remote`. Bind preview services to localhost by default and document any firewall, authentication, and trusted-network requirements. 10. Do not suppress all npm output in the initialization script. Preserve installation errors and security-relevant package information so users and automated monitoring can detect unexpected package behavior. ]]>
