T08 · Insecure Dependencies
- Location
SKILL.md:228- Finding
Unpinned Package Retrieval and Execution Through npx
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 228
Vulnerability Type: Unpinned third-party dependency retrieval and execution
Risk Level: MediumVulnerable Code
bash npx lighthouse https://example.com --output html --output-path ./report.htmlTechnical Analysis
The documented
npx lighthousecommand does not specify an audited package version. If Lighthouse is unavailable locally,npxmay retrieve the currently resolved package and its dependency tree from the configured npm registry before executing it.Because registry content is mutable after the Skill itself has been reviewed, the effective executable payload is not fully represented by the audited project. A compromised package release, npm account, registry mirror, or transitive dependency could therefore introduce arbitrary code. The Lighthouse operation is relevant to the declared performance-auditing functionality, but unpinned package execution is not the minimum-risk implementation.
Attack Path
- An attacker compromises a relevant npm package, maintainer account, registry path, or transitive dependency.
- A malicious package version becomes the version resolved by the unpinned
npx lighthousecommand. - A user or Agent follows the Skill documentation and runs the command.
npxretrieves the mutable package content when no suitable local installation is available.- Malicious installation or runtime code executes with the permissions and environment of the invoking account.
Impact Assessment
Successful exploitation could permit arbitrary code execution under the invoking user's privileges. Depending on sandboxing and host permissions, the compromised dependency could read or alter accessible project files, inspect process environment data, create network connections, modify user-scoped configuration, or tamper with generated audit reports. The Skill does not itself demonstrate such malicious behavior; ...[truncated 62 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Lighthouse to a specifically reviewed version rather than resolving the latest available release.
- Install dependencies from a committed lockfile with integrity hashes.
- Prefer a project-local development dependency over implicit
npxdownloading. - Use a command that refuses automatic package installation when supported.
- Run Lighthouse in a container or restricted sandbox with only the required output directory mounted as writable.
- Restrict access to credentials, environment variables, unrelated files, and unnecessary network destinations.
- Establish a dependency-update process that includes provenance, vulnerability, and integrity review before changing the pinned version.
