T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned and Unused Global npm Dependency Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:11
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
yaml dependencies: "npm install -g @aspect-ratio/preview-renderer"Technical Analysis
The Skill metadata instructs users or the hosting framework to install
@aspect-ratio/preview-rendererglobally without specifying an exact version, lockfile, or integrity hash. This resolves a mutable package release from the npm registry at installation time.npm packages can execute lifecycle scripts during installation. Consequently, compromise of the named package, its publication credentials, or a future release could cause arbitrary code to execute with the privileges of the account installing the Skill.
The audited project does not import or invoke this package. Preview rendering is implemented directly through headless Chrome in
scripts/chrome-utils.mjsandscripts/render-preview.mjs. The global dependency therefore creates supply-chain exposure without supporting the reviewed execution path.Attack Path
- An attacker compromises the npm package, its maintainer account, or a future release.
- The attacker publishes a malicious version containing npm lifecycle code.
- A user or Agent installs the Skill and executes the declared command:
sh npm install -g @aspect-ratio/preview-renderer - npm retrieves the mutable package version and runs its applicable lifecycle scripts.
- The malicious code executes under the installing user's privileges and can access resources available to that account.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installation. Depending on that account's permissions, the malicious package could read or modify user-accessible files, environment variables, project data, and globally installed Node.js components.
...[truncated 193 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove the dependency declaration because no audited script uses
@aspect-ratio/preview-renderer. - If the package becomes necessary, install it locally rather than globally.
- Pin an exact reviewed version instead of resolving the latest release.
- Commit and enforce a lockfile with integrity metadata.
- Verify package ownership, provenance, publication history, and source repository before adoption.
- Review the package and transitive dependencies for lifecycle scripts.
- Disable npm lifecycle scripts where operationally feasible, then explicitly run only required build steps.
- Execute installation and rendering in a restricted environment with minimal filesystem, network, credential, and environment-variable access.
- Add automated dependency scanning and controlled update review before accepting future versions.
- Remove the dependency declaration because no audited script uses
