T08 · Insecure Dependencies
- Location
scripts/wx-miniprogram-ci.js:466- Finding
Automatic Unpinned Global Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/wx-miniprogram-ci.js, lines 466-476
Vulnerability Type: Supply-chain risk caused by automatic installation of an unpinned global dependency
Risk Level: MediumVulnerable Code
javascript function ensureGlobalMiniprogramCi() { const { execSync } = require('child_process'); try { execSync('miniprogram-ci --version', { stdio: 'ignore' }); log('miniprogram-ci 已全局安装', 'success'); return true; } catch (e) { log('miniprogram-ci 未全局安装,正在进行全局安装...', 'info'); try { execSync('npm install -g miniprogram-ci', { stdio: 'inherit', shell: process.platform === 'win32' });Technical Analysis
The skill automatically runs
npm install -g miniprogram-ciwhen the corresponding executable cannot be found. It does not pin an exact audited version, use a lockfile, verify an integrity digest, or constrain the npm registry.Consequently, the effective dependency code may change after this skill has been reviewed. npm installation can also execute package lifecycle scripts. Because the dependency is installed globally, such scripts execute with the permissions of the user running the skill and can affect globally accessible files and tooling.
This behavior is also explicitly documented in
SKILL.md, lines 80-84:markdown 初始化环境: 1. 检查是否已全局安装 `miniprogram-ci` 2. 如果未安装则执行 `npm install -g miniprogram-ci` 3. 保持当前脚本作为配置管理和全局 CLI 调用层Attack Path
- The user invokes
init,preview,upload, or another command that callsensureGlobalMiniprogramCi(). - The
miniprogram-ci --versioncheck fails because the executable is absent, unavailable throughPATH, or otherwise cannot execute. - The skill invokes the configured npm client to resolve the current
miniprogram-cipackage from the active registry. - If the package, registry, package publisher, or dependency chain has been compromised, attacker-controlled installation or lifecycle code e ...[truncated 758 chars]
- The user invokes
- Remediation
View remediation
Remediation Suggestions
- Declare an exact audited
miniprogram-civersion in a localpackage.json; do not use a floating version. - Commit a lockfile containing dependency versions and integrity metadata.
- Install dependencies locally with
npm cirather than automatically modifying the global npm environment. - Invoke the project-local executable through a controlled path, such as
node_modules/.bin/miniprogram-ci, instead of relying onPATH. - Avoid automatic installation during operational commands. If the dependency is missing, fail safely and provide explicit installation instructions.
- Enforce a trusted npm registry and validate the resolved package source and integrity.
- Review lifecycle scripts and consider installation controls appropriate to the dependency, such as disabling scripts where compatible.
- Run CI tooling under a dedicated, non-privileged account with access limited to the required project, key, and output paths.
- If global installation is unavoidable, require explicit user confirmation, pin the exact version, verify it before execution, and never perform the installation with elevated privileges.
- Declare an exact audited
