T08 · Insecure Dependencies
- Location
SKILL.md:65- Finding
Unpinned Third-Party Package Installed Globally
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 65
Vulnerability Type: Unpinned third-party dependency and unaudited binary installation
Risk Level: MediumVulnerable Code
bash npm install -g @never-sleeps/mns-cliTechnical Analysis
The installation procedure retrieves the current published version of
@never-sleeps/mns-cliwithout specifying a version or verifying an integrity digest. It installs the package globally, while the executable package and its source code are not included in the audited project.Consequently, the effective code executed by the skill can change after this review. A compromised npm account, malicious package release, registry compromise, or compromised transitive dependency could introduce arbitrary installation or runtime behavior. Global installation increases exposure by making the resulting executable available beyond the immediate skill run.
Attack Path
- An attacker compromises the npm package, its publisher account, release process, or a dependency used by the package.
- The attacker publishes a malicious release under the expected package name.
- An agent follows the documented setup command on a system where
mnsis unavailable. - npm resolves and downloads the attacker-controlled release because no audited version or integrity value is pinned.
- Malicious lifecycle scripts or the installed executable run with the permissions of the user invoking npm.
- The payload accesses or modifies resources available to that user.
Impact Assessment
Successful exploitation could permit arbitrary code execution with the invoking user's privileges. The resulting scope may include reading or modifying user-accessible files, configuration, portfolio records, environment variables, and credentials; making network requests; and installing a globally accessible command. No evidence establishes administrative privilege escalation, so impact is limite ...[truncated 121 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specifically audited version, for example:
bash npm install -g @never-sleeps/mns-cli@0.6.0 - Verify the package archive against a publisher-provided cryptographic digest or trusted signed provenance before installation.
- Publish reproducible-build information and checksums for every platform-specific binary.
- Avoid global installation where possible. Use a project-local dependency or an isolated, least-privileged environment.
- Disable npm lifecycle scripts during installation if the package does not require them:
bash npm install --ignore-scripts @never-sleeps/mns-cli@0.6.0 - Audit the package contents, installation scripts, binary provenance, and transitive dependencies before approving the pinned release.
- Configure automated monitoring for package ownership changes, unexpected releases, integrity changes, and dependency vulnerabilities.
- Pin the dependency to a specifically audited version, for example:
