T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned Third-Party Packages Are Installed and Executed Globally
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25-31
Vulnerability Type: Unpinned dependency installation and execution
Risk Level: MediumVulnerable Code
bash npm install -g @tencent-qqmail/agently-cliStep 2 — Install/update the skill:
bash npx skills add Tencent/AgentlyMail -g -yTechnical Analysis
The installation instructions resolve and execute third-party npm packages without pinning exact versions or verifying package integrity.
npm install -g @tencent-qqmail/agently-cliinstalls the currently resolved package release globally. Depending on npm configuration and package contents, installation can execute package lifecycle scripts with the privileges of the invoking user.The
npx skills ... -ycommand similarly resolves and executes theskillscommand while automatically accepting installation prompts. The-yoption reduces the opportunity for the user to inspect or reject an unexpected package resolution. Neither command uses an exact reviewed version, lockfile, cryptographic integrity value, or locally audited artifact.The external package implementations are not included in this project and therefore could not be reviewed as part of this audit. The issue is an unsafe supply-chain boundary rather than evidence that the referenced packages are currently malicious.
Attack Path
- An attacker compromises a referenced npm package, its publisher account, or its release pipeline.
- Alternatively, an unexpected or malicious future package version is published under a dependency resolved by one of the commands.
- A user follows the skill instructions and runs the unpinned global installation or
npxcommand. - npm retrieves the mutable package version available at execution time.
- Malicious package code or lifecycle scripts execute with the privileges of the invoking user.
- The malicious code can access resources available to that user, ...[truncated 921 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin every executable package to a reviewed exact version, for example:
bash npm install -g @tencent-qqmail/agently-cli@<reviewed-version> npx --package=skills@<reviewed-version> skills add Tencent/AgentlyMail -g -
Remove automatic approval through
-yso users can review unexpected package installation prompts. -
Prefer a project-local installation governed by a committed lockfile instead of modifying global package state.
-
Verify package provenance, signatures, checksums, and npm registry configuration before installation. Consider using npm provenance attestations where available.
-
Audit package lifecycle scripts and published package contents before approving version updates.
-
Execute installation with a non-privileged account and avoid
sudoor administrator shells. -
Use an allowlisted internal registry or mirror containing reviewed package artifacts for security-sensitive deployments.
-
Document an explicit version-update and security-review process instead of always installing the latest available release.
-
