T08 · Insecure Dependencies
- Location
README.md:62- Finding
Unpinned Third-Party CLI Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 62–72 and line 80
Vulnerability Type: Supply-chain risk from an unpinned executable dependency
Risk Level: MediumComplete Code Snippet:
bash npx skills add skcache/ednbash npx skills add skcache/edn -a codexbash npx skills add skcache/edn -a claude-codebash npx skills update ednTechnical Analysis
The documented installation and update procedures invoke the third-party
skillspackage throughnpxwithout specifying an exact reviewed version or an integrity constraint. If the package is not already available locally,npxcan resolve and execute a mutable package release from the configured npm registry.This means the code executed during installation is not contained within, or fixed by, the audited project. A future package release, compromised maintainer account, compromised registry, or malicious dependency introduced into the CLI could change the effective executable payload after this Skill has been reviewed.
No evidence was found that the current
skillspackage is malicious. The issue is the absence of version and integrity controls around executable supply-chain content.Attack Path
- An attacker compromises the package, its publisher account, its dependency chain, or the package source used by the configured npm registry.
- The attacker publishes a malicious release that can be selected by the unpinned
npx skillscommand. - A user follows the installation or update instructions in
README.md. npxdownloads or resolves the attacker-controlled release.- The package's CLI code, and potentially applicable package installation scripts, execute with the user's privileges.
- The malicious code can access or modify resources available to that user before or while performing the expected installation operation.
Impact Assessment
Successful exploitation wou ...[truncated 805 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to a specifically reviewed version in every installation command, for example:
bash npx --yes skills@<reviewed-version> add skcache/edn -
Use the same pinned version for agent-specific installation and update operations. Avoid allowing an update command to execute an automatically selected future CLI release.
-
Document the authoritative npm package name, publisher, source repository, and expected package provenance so users can identify dependency-confusion or impersonation attempts.
-
Where supported, verify package integrity or provenance before execution. Prefer a lockfile-backed installation workflow for controlled environments.
-
Review new CLI releases before changing the documented version. Record the reviewed version and update it deliberately rather than relying on mutable registry resolution.
-
Recommend running installation with a minimally privileged development account and without unnecessary secrets in the process environment.
-
