T08 · Insecure Dependencies
- Location
SKILL.md:102- Finding
Unpinned Third-Party Package Is Downloaded and Executed Automatically
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 102-106; repeated at line 325
Vulnerability Type: Unpinned dependency execution and software supply-chain exposure
Risk Level: MediumVulnerable Code
json { "protocolServers": { "connector-diagram-generator": { "command": "npx", "args": ["-y", "connector-diagram-generator"] } } }The same unsafe installation pattern is repeated in the setup guidance:
text Set `command` to `npx` and `args` to `["-y", "connector-diagram-generator"]`.Technical Analysis
The Skill directs users to invoke
connector-diagram-generatorthroughnpx -ywithout specifying an exact package version, integrity hash, lockfile, trusted registry, or verified publisher identity.When the package is not already available locally,
npxcan retrieve it from the configured npm registry and execute its entry point. The-yoption suppresses the normal installation confirmation. Consequently, the executable code run by the Agent is not immutable: it may differ from the code that existed when this Skill was reviewed.This creates a supply-chain boundary in which compromise of the package publisher, npm account, registry resolution, or a transitive dependency could result in arbitrary code execution. The audit could not verify the connector because the project contains only
SKILL.md; it does not include the connector source, a package manifest, a lockfile, or integrity metadata.Attack Path
- An attacker compromises the
connector-diagram-generatorpackage, its publisher account, or one of its resolved dependencies. - The attacker publishes a malicious version under the package name used by the Skill.
- A user follows the documented setup instructions.
npx -y connector-diagram-generatorresolves and downloads the mutable package version without requesting interactive confirmation.npxexecutes the package entry point with the privileges and environment o ...[truncated 1237 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin the connector to an exact, reviewed version rather than resolving the latest mutable release:
json { "protocolServers": { "connector-diagram-generator": { "command": "npx", "args": [ "--yes", "--package=connector-diagram-generator@1.2.3", "connector-diagram-generator" ] } } } -
Record and verify package integrity through a committed lockfile and registry-provided integrity hashes. Prefer a controlled installation step such as
npm ciover runtime package resolution. -
Verify and document the expected package publisher, package registry, source repository, and reviewed release checksum. Reject packages resolved from unexpected registries.
-
Avoid unattended
-yinstallation where practical. Separate dependency installation and approval from connector execution so users can inspect the resolved version before running it. -
Prefer vendoring or bundling a reviewed connector artifact when operationally feasible. Sign releases and verify signatures or checksums before execution.
-
Run the connector in a restricted environment:
- Use a dedicated unprivileged operating-system account.
- Limit filesystem access to required input and output directories.
- Expose only essential environment variables.
- Do not pass unrelated credentials or API keys.
- Restrict outbound network access to explicitly required destinations.
- Apply process, resource, and execution limits.
-
Add an upgrade-review process so version changes require source review, dependency scanning, integrity regeneration, and regression testing before deployment.
-
Update both occurrences of the setup instruction, including the repeated guidance at line 325, to prevent users from falling back to the unsafe command.
-
