T08 · Insecure Dependencies
- Location
README.md:118- Finding
Unpinned Third-Party Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md:118,README.md:126; duplicated inREADME_ZH.md:118,127andSKILL.md:32,68
Vulnerability Type: Unpinned packages installed directly from public registries
Risk Level: MediumVulnerable Code
bash pip install agent-reachbash npm install -g @steipete/birdTechnical Analysis
The installation instructions retrieve the latest available releases from public Python and npm registries without specifying reviewed versions, cryptographic hashes, lockfiles, or integrity metadata. Consequently, the code installed by a user can change after the Skill itself has been audited.
The npm dependency is installed globally, increasing the potential effect of a compromised package. npm installation can invoke package lifecycle scripts, while Python packages can execute build-related code during installation. A compromised publisher account, malicious future release, dependency takeover, or compromised transitive dependency could therefore result in arbitrary code execution during installation.
No evidence establishes that either named package is currently malicious. The vulnerability is the unsafe and non-reproducible dependency acquisition process.
Attack Path
- An attacker compromises a dependency publisher, package release process, or relevant transitive dependency.
- The attacker publishes a malicious release under the package name referenced by the documentation.
- A user follows the documented commands without selecting a reviewed version.
- The package manager resolves and downloads the attacker-controlled release.
- Malicious installation, build, or lifecycle code executes with the privileges of the user running the package manager.
- For the globally installed npm package, the malicious package may also place commands in globally accessible executable locations.
Impact Assessment
Successful exploitation could execut ...[truncated 422 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin every direct dependency to a specifically reviewed version.
- For Python, provide a locked requirements file with cryptographic hashes and require hash verification, for example through
pip install --require-hashes. - For npm, provide a lockfile and use a reproducible installation mechanism such as
npm ci. - Document the expected package publisher, version, and integrity digest.
- Review and lock transitive dependencies rather than relying only on direct version constraints.
- Avoid global npm installation where possible. Install the CLI in a dedicated project directory or isolated environment.
- Disable package lifecycle scripts during installation when they are unnecessary, and review any scripts that must remain enabled.
- Establish a dependency update process in which new versions are reviewed before documentation pins are changed.
