T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned Third-Party Package Is Automatically Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 29–42
Vulnerability Type: Unpinned package execution throughnpx -y
Risk Level: MediumVulnerable Code Snippet
markdown - Show help (once/session): - `npx -y @steipete/oracle --help` - Preview (no tokens): - `npx -y @steipete/oracle --dry-run summary -p "<task>" --file "src/**" --file "!**/*.test.*"` - `npx -y @steipete/oracle --dry-run full -p "<task>" --file "src/**"` - Token/cost sanity: - `npx -y @steipete/oracle --dry-run summary --files-report -p "<task>" --file "src/**"` - Browser run (main path; long-running is normal): - `npx -y @steipete/oracle --engine browser --model gpt-5.2-pro -p "<task>" --file "src/**"` - Manual paste fallback (assemble bundle, copy to clipboard): - `npx -y @steipete/oracle --render --copy -p "<task>" --file "src/**"`Technical Analysis
The documented commands invoke
npxwith the automatic-confirmation option (-y) and identify the package only as@steipete/oracle, without an exact version. Consequently, package resolution can retrieve and execute whichever release the configured npm registry currently resolves.The reviewed project contains no package lockfile, integrity hash, vendored package source, or other mechanism that binds these commands to an audited artifact. An upstream account compromise, malicious package release, registry compromise, or compromised transitive dependency could therefore alter the code executed after this skill has been reviewed.
Because npm package code runs with the privileges of the user invoking
npx, both package lifecycle behavior and the CLI entry point fall within the local execution trust boundary. The use of-yremoves the normal installation confirmation and makes execution less visible to the user.Attack Path
- An attacker compromises the upstream
@steipete/oraclepackage, one of its depen ...[truncated 1457 chars]
- An attacker compromises the upstream
- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to a reviewed exact version in every command, for example:
sh npx --no-install @steipete/oracleafter installing an exact version through the project dependency manifest and lockfile.
-
Declare the package using an exact version rather than a range:
json { "devDependencies": { "@steipete/oracle": "REVIEWED_EXACT_VERSION" } } -
Commit the generated lockfile and use
npm ciin automated or reproducible environments so dependency resolution cannot silently drift. -
Verify package provenance and registry integrity before adoption. Review the resolved package, transitive dependencies, lifecycle scripts, publisher identity, and published integrity metadata.
-
Where a project-local installation is unsuitable, include an exact version in the
npxpackage specification and establish a controlled process for reviewing and updating that version. -
Avoid
-ywhere unattended confirmation is unnecessary, so unexpected package installation remains visible to the operator. -
Execute the tool with least privilege in an isolated environment. Expose only the files required for the review, avoid secrets in environment variables, and do not provide access to privileged browser profiles or unrelated credentials.
-
