T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party Packages Are Downloaded and Executed
- Content
View full analysis
``` ```bash npm install next@latest react@latest react-dom@latest ``` ```bash npm install @types/react@latest @types/react-dom@latest ``` ### Technical Analysis The skill directs the agent to resolve third-party packages through the mutable `@latest` distribution tag. In particular, `npx @next/codemod@latest` may download and immediately execute package code with the permissions of the agent process. The installation commands also resolve mutable package versions without requiring exact version pinning, lockfile enforcement, integrity verification, package review, or explicit user approval. Package behavior can consequently change after the skill has been reviewed. A compromised package publisher account, registry response, or newly published package version could introduce attacker-controlled code. Package installation may also invoke package lifecycle scripts. ### Attack Path 1. An attacker compromises a relevant package release channel, publisher account, or mutable `latest` tag. 2. The attacker publishes a malicious version or causes the mutable tag to resolve to attacker-controlled package content. 3. An agent follows the skill and invokes the specified `npx` or `npm install` command. 4. The package is retrieved without an exact reviewed version being enforced. 5. The codemod or applicable installation lifecycle code executes with the permissions and environment available to the agent process. 6. The malicious code can access or alter resources available to that process, including project files and any exposed credentials. ### Impact Assessment Successful exploitation could result in arbitrary code execution under the agent process's privileges. The attacker could read or modify the target ...[truncated 428 chars]- Remediation
View remediation
