T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unpinned Security-Sensitive Third-Party SDK Dependency
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:58-60; duplicated inreferences/sdk-typescript.md:12-18
Vulnerability Type: Unpinned third-party dependency and supply-chain exposure
Risk Level: MediumVulnerable Code
SKILL.md:58-60:bash npm install agent0-sdkreferences/sdk-typescript.md:12-18:bash npm install agent0-sdktext Runtime dependencies: `viem ^2.37.5`, `graphql-request ^6.1.0`, `ipfs-http-client ^60.0.1`Technical Analysis
The installation instructions do not pin
agent0-sdkto an exact reviewed version or provide a lockfile or integrity hash. Running the documented command resolves the package version from npm at installation time, so the code installed by users can differ from the version reviewed when this Skill was authored.This dependency is especially security-sensitive because subsequent examples give the SDK access to a wallet private key, a Pinata JWT, RPC configuration, and transaction-signing operations. A compromised publisher account, malicious upstream release, dependency-confusion event, or compromised transitive dependency could therefore run with access to valuable credentials and signing authority. npm lifecycle scripts may also execute during installation.
No evidence establishes that the current package is malicious. The vulnerability is the non-reproducible and insufficiently constrained supply-chain trust boundary.
Attack Path
- An attacker compromises the
agent0-sdknpm publisher, package distribution channel, or a transitive dependency. - The attacker publishes a malicious version under the legitimate package name.
- A user follows the documented unpinned
npm install agent0-sdkcommand. - npm retrieves the attacker-controlled release and may execute its installation lifecycle scripts.
- The user initializes the package with
PRIVATE_KEY,PINATA_JWT, or a browser wallet provider. - Malicious pack ...[truncated 916 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to an exact reviewed version, for example:
bash npm install --save-exact agent0-sdk@1.5.3 -
Distribute a reviewed lockfile and instruct users to install with
npm cirather than dynamically resolving dependency versions. -
Verify package integrity and provenance, including npm provenance attestations and expected registry ownership.
-
Audit the package and its transitive dependencies before supplying wallet or storage credentials.
-
Where compatible, initially install with lifecycle scripts disabled:
bash npm ci --ignore-scripts -
Prefer browser or hardware-wallet signing so the SDK never receives a raw mainnet private key.
-
Use dedicated, low-value testnet keys during development and narrowly scoped credentials for IPFS providers.
-
Add dependency update review and automated supply-chain scanning before changing the pinned version.
-
