T08 · Insecure Dependencies
- Location
README.md:24- Finding
Unpinned npm Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
README.md:24-34
Additional Location:README.zh.md:22-32
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumVulnerable Code
markdown Install through npm and run the installer with `npx`: ```bash npx @swarmclawai/andrej-karpathy-skills --list npx @swarmclawai/andrej-karpathy-skills --agent codex --dest /path/to/projectOr install the CLI globally:
bash npm install -g @swarmclawai/andrej-karpathy-skillstext ### Technical Analysis The documented installation commands retrieve the package under its unqualified package name, without specifying an audited version or integrity digest. Consequently, npm resolves the current registry version at installation time. The code that users execute can therefore change after this Skill artifact has been reviewed. The risk is aggravated by the incomplete audit boundary. `package.json:6-10` maps both command names to `scripts/install.mjs`, but that script is absent from the supplied artifact: ```json "bin": { "andrej-karpathy-skills": "scripts/install.mjs", "karpathy-skills": "scripts/install.mjs" }The installer executed from the npm registry therefore cannot be compared with or validated against the files supplied for this audit. Although this audit found no evidence that the current package is malicious, the instructions create an unsafe supply-chain execution path in which a compromised publisher account, registry response, or future release could replace the reviewed behavior.
Attack Path
- An attacker compromises the npm publisher account, package publication workflow, or another component capable of releasing a new version of
@swarmclawai/andrej-karpathy-skills. - The attacker publishes a modified package whose declared CLI entry point performs malicious actions.
- A user follows the documented unpinned
npxcommand or globally ins ...[truncated 1016 chars]
- An attacker compromises the npm publisher account, package publication workflow, or another component capable of releasing a new version of
- Remediation
View remediation
Remediation Suggestions
-
Pin all installation examples to a specific audited release:
bash npx @swarmclawai/andrej-karpathy-skills@1.0.0 --list npx @swarmclawai/andrej-karpathy-skills@1.0.0 --agent codex --dest /path/to/project npm install -g @swarmclawai/andrej-karpathy-skills@1.0.0 -
Publish and document the expected npm package integrity digest. Where practical, verify the downloaded tarball against a digest distributed through a separately protected release channel.
-
Include
scripts/install.mjsand every packaged adapter in the reviewed source artifact so the executable behavior can be audited directly. -
Add reproducible release checks that compare the npm tarball against the corresponding signed source tag, including:
bash npm pack --dry-run npm pack npm audit signatures -
Protect package publication with mandatory multi-factor authentication, provenance attestations, protected release workflows, and narrowly scoped automation tokens.
-
Prefer a download-and-review workflow over immediate remote execution for security-sensitive environments. Users should inspect the package contents before invoking its installer.
-
Clearly state that installation should run as an ordinary user and must not require
sudo, administrator access, or other elevated privileges.
-
