T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned npm Package Execution in Security-Sensitive Wallet Workflows
- Content
View full analysis
`. No global installation required. ``` ```bash npx agentic-wallet providers --json ``` ### Technical Analysis The skill directs agents to run the unversioned `agentic-wallet` npm package through `npx`. No exact version, lockfile, integrity hash, verified local installation, or package provenance check is specified. Depending on the local npm and `npx` configuration, the command can download and execute the package currently published under that name. Consequently, the effective executable payload can change after this skill has been reviewed. This creates a supply-chain trust boundary between the audited skill documentation and the externally maintained npm package. The risk is particularly significant because subsequent documented commands handle cryptocurrency wallets, recovery seed phrases, wallet encryption passwords, backup files, and Crossmint server API keys. npm package code and applicable installation lifecycle scripts execute with the permissions of the user running `npx`. There is no evidence in the reviewed file that the current `agentic-wallet` package is malicious. The vulnerability is the unsafe, unpinned execution model and the absence of controls that ensure future executions use the reviewed artifact. ### Attack Path 1. An attacker compromises the npm publisher account, package repository, release process, or another component of the package supply chain. 2. The attacker publishes a malicious version under the existing `agentic-wallet` package name. 3. An agent follows `SKILL.md` and executes an unversioned command such as `npx agentic-wallet providers --json`. 4. `npx` retrieves or resolves the attacker-controlled release. 5. Package code or installation lifecycle scripts execute wit ...[truncated 1141 chars]- Remediation
View remediation
