T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned npm Dependency Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 11-15
Vulnerability Type: Unpinned third-party dependency
Risk Level: MediumVulnerable Code:
yaml install: - id: npm kind: node package: axios bins: ["axios"]Technical Analysis
The Skill requests installation of the npm package
axioswithout specifying an exact version, lockfile, or integrity hash. Consequently, installation may resolve to mutable package-registry state rather than a dependency version reviewed during the audit.If the package, one of its transitive dependencies, or the relevant registry account is compromised, a malicious release could introduce attacker-controlled code. Depending on package-manager configuration, lifecycle scripts may execute during installation. The declared
axiosexecutable is also not justified by the documented content-generation behavior, increasing the supply-chain attack surface without a demonstrated functional requirement.Attack Path
- An attacker compromises the npm package publication process, a maintainer account, the package registry, or a transitive dependency.
- The attacker publishes a malicious version that satisfies the unrestricted dependency declaration.
- A user installs or deploys the Skill after the malicious release becomes available.
- The package manager resolves and downloads the attacker-controlled release.
- Malicious lifecycle code may execute during installation, or malicious library behavior may execute when the dependency is used.
- The payload operates with the permissions of the account or environment performing the installation.
Impact Assessment
Successful exploitation could allow code execution with installer-level privileges. Depending on the deployment environment, the attacker could access files, environment variables, API credentials, network resources, and other data available to the installing ...[truncated 212 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove
axiosif it is not required by any implemented Skill behavior. - If it is required, pin it to a reviewed exact version rather than using an unrestricted package declaration.
- Use a committed lockfile and verify package integrity through trusted checksums or registry integrity metadata.
- Review and pin all transitive dependencies where the installation system supports it.
- Disable npm lifecycle scripts during installation when they are unnecessary, for example by using an equivalent of
--ignore-scripts. - Install dependencies in a sandboxed, non-privileged environment with minimal filesystem, credential, and network access.
- Document why the dependency and any declared executable are necessary for content generation.
- Add automated dependency scanning and controlled update review before accepting new versions.
- Remove
