T03 · Remote Payload Retrieval and Execution
- Location
references/api.md:34- Finding
Remote Code Execution Through a Mutable GitHub-Hosted npm Dependency
- Content
View full analysis
Vulnerability Details
File Location:
references/api.md:34-36; equivalent commands also appear atSKILL.md:27andreferences/api.md:22-30
Vulnerability Type: Remote payload retrieval and execution
Risk Level: HighComplete Code Snippet:
bash npx -y github:shanye1402-hash/hotbee-social-data-skills#v1.1.0 call hot-rankings --dry-run --platform baidu --platform douyinTechnical Analysis
The documented command instructs the agent to use
npx -yto download and execute a package directly from a third-party GitHub repository. The dependency is identified by the mutable Git tagv1.1.0, rather than an immutable audited commit hash or a package protected by lockfile integrity metadata.The
-yoption automatically accepts package installation without an interactive confirmation. In addition, the documented--dry-runargument is passed to the downloaded application; it does not prevent npm from downloading the dependency or executing applicable package lifecycle behavior before the application handles that argument.The downloaded implementation is not included in this project, so its source, dependency tree, installation hooks, and runtime behavior could not be audited. If the repository, maintainer account, dependency chain, or Git tag is compromised, the externally hosted payload can change after this Skill has been reviewed.
Attack Path
- An attacker compromises the referenced GitHub repository, a maintainer account, or an upstream dependency.
- The attacker moves or replaces the
v1.1.0tag, or otherwise causes the referenced package to resolve to malicious content. - A user or agent follows the Skill documentation and executes the
npx -ycommand. - npm retrieves the attacker-controlled package and may execute its installation lifecycle scripts.
- The malicious package executes with the permissions of the agent process.
- The payload can access files, environment variable ...[truncated 1012 chars]
- Remediation
View remediation
Remediation Suggestions
- Vendor the required implementation into the reviewed project and audit its source code and dependency tree before execution.
- If GitHub retrieval is unavoidable, pin the dependency to a specific audited commit SHA rather than a mutable tag.
- Verify downloaded content against a separately maintained cryptographic digest or signature.
- Avoid
npx -yfor untrusted remote sources. Require explicit user approval before installation and execution. - Disable npm lifecycle scripts where compatible, for example by using
--ignore-scripts, and separately verify that the package does not depend on them. - Run the dependency in a restricted sandbox with minimal filesystem access, a constrained network policy, and no unrelated credentials.
- Expose
HOTBEE_API_KEYonly to the specific process and only for the duration of an approved live request. - Maintain a lockfile or equivalent dependency manifest with integrity metadata for all transitive dependencies.
- Clarify in the documentation that application-level
--dry-rundoes not make remote package installation safe.
