T08 · Insecure Dependencies
- Location
SKILL.md:103- Finding
Unpinned Third-Party Package Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:103
Vulnerability Type: Unpinned and mutable third-party dependency execution
Risk Level: MediumVulnerable Code Snippet:
markdown (install: `npx skills add open-agreements/open-agreements`).Technical Analysis
The skill recommends invoking the
skillsnpm package throughnpxwithout specifying a reviewed version or validating package integrity. If the package is not already installed,npxmay download and execute the version currently published in the configured npm registry.Because package resolution is mutable, the code executed when a user follows this instruction may differ from the code available when the skill was audited. The target repository is likewise not pinned to an immutable commit in this command. A compromised npm account, malicious package update, dependency compromise, registry substitution, or unexpected upstream change could therefore introduce arbitrary installer behavior.
The command is presented as an optional installation recommendation and is not automatically executed by this skill. Exploitation consequently requires a user or agent to follow the recommendation.
Attack Path
- An attacker compromises the resolved
skillsnpm package, one of its executable dependencies, or the repository content retrieved by the installer. - The attacker publishes malicious code under the mutable package or repository reference.
- A user or agent follows the recommendation in
SKILL.mdand runs:shell npx skills add open-agreements/open-agreements npxresolves and downloads the current package version from the configured registry.- The downloaded package executes with the privileges and environment of the invoking user.
- Malicious installer logic can access resources available to that user and may install additional unreviewed content.
Impact Assessment
Successful exploitation co ...[truncated 615 chars]
- An attacker compromises the resolved
- Remediation
View remediation
Remediation Suggestions
- Remove the executable installation command from the legal-information skill unless it is essential to the skill's primary purpose.
- If installation guidance must remain, pin the CLI to a specifically reviewed version rather than relying on mutable resolution, for example:
shell npx --yes skills@<reviewed-version> add open-agreements/open-agreements - Pin the installed repository or package content to an immutable release or commit where the installer supports it.
- Verify package integrity through an approved lockfile, cryptographic digest, signed release, or trusted internal registry.
- Require explicit, informed user approval immediately before executing any package-manager command. The agent must not run the command automatically.
- Execute installation in a sandbox with minimal filesystem, credential, and network access.
- Review the CLI package, its transitive dependencies, and the exact target revision before recommending or executing the installation.
