T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 14-18
Vulnerability Type: Unpinned and globally installed third-party dependency
Risk Level: MediumVulnerable Code:
markdown ## Setup If `readwise` is not installed: ```bash npm install -g @readwise/clitext ### Technical Analysis The Skill directs the agent to retrieve the latest available version of `@readwise/cli` from npm and install it globally. It does not specify a reviewed version, lockfile, expected integrity hash, or other provenance verification mechanism. npm packages can execute lifecycle scripts during installation. Because the effective package contents may change after this Skill has been audited, a compromised or unexpectedly modified package release could execute arbitrary code under the privileges of the user performing the installation. Global installation also increases the affected scope by placing executables and package files into shared user-level or system-level npm locations. The audit found no evidence that the named package is currently malicious. The vulnerability is the Skill's unsafe dependency acquisition and installation practice. ### Attack Path 1. An attacker compromises the npm publisher account, package distribution channel, or a future release of `@readwise/cli`. 2. The attacker publishes a release containing malicious installation or runtime code. 3. An agent follows the Skill instructions and executes `npm install -g @readwise/cli`. 4. npm downloads the attacker-controlled current release without checking it against a version or integrity value approved by the Skill author. 5. Malicious lifecycle code may execute during installation, or malicious CLI code may execute when the `readwise` command is subsequently invoked. 6. The payload operates with the permissions of the installing user and may modify user-accessible files, credentials, or globally installed npm tooling. ### Impact Assess ...[truncated 389 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
@readwise/clito a specific version that has been reviewed, rather than implicitly installing the latest release. - Record and verify the expected package integrity or provenance before installation.
- Document the expected npm registry to reduce registry substitution and configuration-related supply-chain risks.
- Prefer a project-local installation over a global installation so that the package is isolated and represented in a lockfile.
- Commit an npm lockfile where applicable and use a reproducible installation mechanism such as
npm ci. - Avoid elevated installation privileges and explicitly warn users not to run the installation through
sudo. - Consider disabling lifecycle scripts with
--ignore-scriptsif the reviewed CLI can be installed and operated correctly without them.
- Pin
