T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Third-Party Package Installation and Execution
- Content
View full analysis
``` The same unpinned `npx @openindex/openindexcli` invocation is repeated throughout `SKILL.md:31-213`. ### Technical Analysis The skill instructs users and agents to globally install or directly execute the latest available version of `@openindex/openindexcli`. It does not specify an exact version, lockfile, package integrity hash, trusted artifact digest, or other mechanism for verifying the downloaded executable. An `npx` invocation may download package code at execution time. Consequently, the effective code executed by the skill can change after the skill itself has been reviewed. A malicious package release, compromised publisher account, registry compromise, or dependency-chain compromise could introduce arbitrary code without any modification to `SKILL.md`. This is particularly sensitive because the external CLI is intended to process private keys, encrypted messages, identities, recipient addresses, and cryptocurrency transactions. The supplied project contains no implementation of the CLI, so its behavior and security claims cannot be independently verified from the audited artifact. ### Attack Path 1. An attacker compromises the npm package, its publisher account, or one of its transitive dependencies. 2. The attacker publishes a malicious version under the existing package name. 3. A user or agent follows the skill instructions and runs either: - `npm install -g @openindex/openindexcli`, or - `npx @openindex/openindexcli ...`. 4. The package manager downloads and executes the attacker-controlled package or lifecycle code. 5. The malicious code reads process-accessible secrets, environment variables, wallet keys, ...[truncated 990 chars]- Remediation
View remediation
``` Do not use version ranges or floating tags such as `latest`. 2. Publish and verify the expected package tarball integrity hash or cryptographic signature before execution. 3. Include a lockfile and retain reviewed dependency versions where a local installation is used. 4. Prefer vendoring the reviewed source code in the project or linking to a reproducible, signed release whose source and build process can be audited. 5. Avoid global installation unless it is operationally necessary. Execute the package in a restricted environment with minimal filesystem, network, and secret access. 6. Disable npm lifecycle scripts where compatible with the package: ```bash npm install --ignore-scripts --save-exact @openindex/openindexcli@X.Y.Z ``` 7. Review the CLI and all transitive dependencies before allowing it to handle wallet keys or authorize financial transactions. 8. Require explicit transaction confirmation that independently displays the resolved chain, recipient address, token contract, and amount. ]]>
