T08 · Insecure Dependencies
- Location
SKILL.md:20- Finding
Unpinned Slidev Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 20
Vulnerability Type: Unpinned third-party package execution
Risk Level: MediumComplete Code Snippet:
bash pnpm create slidev # Create projectTechnical Analysis
The documented command resolves a package through the user's configured package registry without specifying a vetted version or integrity constraint. Project-creation packages execute code locally as part of initialization, so the effective code can change after this Skill has been audited.
This creates a supply-chain exposure if the package, publisher account, registry, or local registry configuration is compromised. The audit found no evidence that the Skill's author intentionally supplies a malicious package; the issue is the unsafe, mutable dependency resolution process.
Attack Path
- An attacker compromises the relevant package publication channel or causes the user to resolve packages through a malicious registry.
- The attacker publishes or serves a modified package version containing malicious initialization or lifecycle code.
- A user follows the Skill and runs
pnpm create slidev. - pnpm retrieves the currently resolved, unpinned package.
- The package code executes with the permissions and environment of the invoking user.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's account. The accessible scope may include the presentation project, other files writable by that user, environment variables exposed to the process, available developer credentials, and network resources reachable from the host. This command does not itself request elevated privileges, so system-wide or administrative access would require the user to run it with such privileges or the attacker to exploit an additional privilege-escalation flaw.
- Remediation
View remediation
Remediation Suggestions
- Specify an explicitly vetted Slidev initializer version rather than resolving the latest available version.
- Use the expected official registry explicitly in controlled environments.
- Review the selected package version, its publisher, provenance, and lifecycle scripts before execution.
- Generate and commit a lockfile containing integrity metadata for the resulting project.
- Enforce lockfile-based, immutable installation in CI.
- Run project initialization as an unprivileged user in an isolated workspace without unnecessary secrets in the environment.
