T08 · Insecure Dependencies
- Location
references/install.md:29- Finding
Unpinned Global Installation of a Mutable Third-Party Dependency
- Content
View full analysis
Vulnerability Details
File Location:
references/install.md, lines 29-34
Vulnerability Type:T08: Insecure Dependencies
Risk Level: HighVulnerable Code
bash npm install -g @autolabz/ftc-cli@latestVerification:
bash ftc -vTechnical Analysis
The installation workflow directs the Agent to install the mutable
latestversion of@autolabz/ftc-cliglobally. The package is neither pinned to a previously audited version nor validated using an integrity digest or trusted provenance information.Because the
latesttag can be reassigned after this Skill has been reviewed, the code executed during a future installation may differ from the version originally expected. An attacker who compromises the package, its publisher account, or its distribution channel could publish a malicious release. Package installation may also invoke npm lifecycle scripts, allowing code to execute during installation before the subsequent version check occurs.The global installation scope increases exposure because the resulting executable is placed in the user's global command environment and can subsequently be invoked outside this Skill.
Attack Path
- An attacker compromises the npm package, publisher credentials, or package distribution process.
- The attacker publishes a malicious version and assigns it to the
latesttag. - The Agent follows the installation instructions and executes
npm install -g @autolabz/ftc-cli@latest. - Malicious package code or lifecycle scripts execute with the privileges of the account running the Agent.
- The installed global
ftcexecutable remains available for later calls and may intercept authentication information, alter requests, access user files, or execute additional commands.
Impact Assessment
Successful exploitation can provide arbitrary code execution with the operating-system privileges of the Agent user. The attacker may access ...[truncated 377 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Record and verify the package integrity digest and package provenance before installation.
- Prefer a project-local or isolated installation over a global installation.
- Inspect package contents and lifecycle scripts before approving upgrades.
- Consider installing with lifecycle scripts disabled during initial validation, then enable only scripts proven necessary.
- Require explicit user approval before installing or upgrading executable third-party packages.
- Maintain an allowlist of approved package names, versions, registries, and publisher identities.
- Run the CLI under a minimally privileged account or sandbox with restricted file and network access.
- Replace
