T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Execution of an Unverified Third-Party npm Package
- Content
View full analysis
``` Or, if you prefer a global install, the skill's `metadata.SkillHub.install` field declares the exact pinned version (`npm install -g @dlazy/cli@1.2.0`). Review the GitHub source before installing. ``` ### Technical Analysis The skill instructs the agent to download and execute `@dlazy/cli` from the npm registry through `npx`, or to install it globally. The package source is not included in the audited project, so its runtime behavior, transitive dependencies, and npm lifecycle scripts cannot be verified from the artifact. Version provenance is also inconsistent: the document claims that the package is pinned to `1.0.9`, while both executable installation examples use `1.2.0`. No lockfile, package integrity hash, verified source URL, or signature is provided. Version pinning alone does not establish package integrity if the registry account, package distribution channel, or a transitive dependency is compromised. Running `npx` creates a code-execution channel for externally distributed package code. A global installation increases persistence and makes the executable available outside the immediate skill invocation. ### Attack Path 1. A user asks the agent to generate image, video, or audio content. 2. The skill directs the agent to run `npx @dlazy/cli@1.2.0` or install that package globally. 3. npm retrieves the package and its dependencies from an external registry. 4. Package lifecycle scripts and CLI code execute with the privileges of the agent process. 5. If the package, publisher account, registry response, or a transitive depe ...[truncated 1214 chars]- Remediation
View remediation
