T08 · Insecure Dependencies
- Location
SKILL.md:81- Finding
Unpinned npm Package Execution and Global Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 81-86
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
sh # Run directly (no install needed) npx @microsoft/learn-cli search "BlobClient UploadAsync Azure.Storage.Blobs" # Or install globally, then run npm install -g @microsoft/learn-cli mslearn search "BlobClient UploadAsync Azure.Storage.Blobs"Technical Analysis
The documented fallback commands resolve
@microsoft/learn-cliwithout specifying an exact version or verifying package integrity. Consequently, npm retrieves whichever release the registry currently identifies as the applicable latest version.The
npxcommand can download and immediately execute package code. The alternative global installation persists the package in the user's global npm environment and may run npm lifecycle scripts during installation. Although the package name and publisher scope are consistent with the skill's stated purpose, the instructions do not protect against a compromised publisher account, malicious or defective future release, or npm registry supply-chain compromise.Attack Path
- An attacker compromises the npm package, its publisher account, or the associated release process.
- The attacker publishes a malicious version under the legitimate
@microsoft/learn-clipackage name. - A user follows the fallback instructions in
SKILL.md. - Because no exact version or integrity value is specified, npm retrieves the attacker-controlled release.
npximmediately runs the package, ornpm install -ginstalls it globally and may execute lifecycle scripts.- The malicious package executes with the privileges of the invoking user and can access resources available to that account.
Impact Assessment
Successful exploitation could provide arbitrary code execution under the invoking user's account. Depending on that account's ...[truncated 592 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, reviewed version, for example:
sh npx @microsoft/learn-cli@X.Y.Z search "BlobClient UploadAsync Azure.Storage.Blobs" - Verify the selected release's provenance and integrity before recommending it. Where practical, document the expected npm integrity hash or use a lockfile in a controlled wrapper project.
- Disable npm lifecycle scripts with
--ignore-scriptsif the CLI functions correctly without them:sh npx --ignore-scripts @microsoft/learn-cli@X.Y.Z search "BlobClient UploadAsync Azure.Storage.Blobs" - Remove the global installation recommendation. Prefer an ephemeral, pinned invocation or a locally installed dependency governed by a committed lockfile.
- Prefer the Microsoft Learn MCP endpoint described by the skill when it is available, reducing the need to download and execute a local npm package.
- Advise users to run the CLI without elevated privileges and in an environment that does not expose unrelated credentials or sensitive files.
- Pin the CLI to an exact, reviewed version, for example:
