T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:24andISSUE.md:70
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumVulnerable Code Snippets
SKILL.md:24:bash npm install -g openapi-to-cliISSUE.md:70:bash npm install -g openapi-to-cliTechnical Analysis
The installation instructions retrieve the current npm release of
openapi-to-cliwithout specifying an exact reviewed version or verifying an integrity digest. Consequently, the package installed by a user can differ from the package that existed when this Skill was audited.npm packages may contain lifecycle scripts that execute during installation. The global installation option (
-g) also places the package and its executable in the user's global npm environment. If a future release or the package's publishing account is compromised, following these instructions could execute unreviewed code with the privileges of the user running npm and replace the globally availableocliexecutable.This is a supply-chain weakness rather than evidence that the current
openapi-to-clipackage is malicious.Attack Path
- An attacker compromises the npm publisher account, release process, or another component of the package's dependency chain.
- The attacker publishes a malicious version under the legitimate package name.
- A user follows the documented
npm install -g openapi-to-cliinstruction. - npm resolves the mutable latest version rather than a previously audited version.
- Malicious lifecycle scripts can execute during installation, or malicious package code can execute when the agent later invokes
ocli. - Because
ocliis intended to manage API profiles and issue authenticated API requests, malicious code running in that process could access credentials available to it, alter requests, or disclose API responses.
Impact Assessment
Successful exploitation would provide code execution with the priv ...[truncated 587 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the dependency to a specific reviewed version, for example:
bash npm install -g openapi-to-cli@<reviewed-version> -
Verify the package provenance, publisher identity, release signatures, and expected integrity digest before installation.
-
Prefer a project-local installation governed by a committed lockfile instead of a global installation where operationally practical.
-
Use
npm ciwith a reviewed lockfile in controlled deployments to ensure deterministic dependency resolution. -
Disable npm lifecycle scripts during installation with
--ignore-scriptsif the package functions correctly without them. If scripts are required, review them before execution. -
Avoid running npm as root or through
sudo; install and execute the CLI under a dedicated, least-privileged account. -
Grant API bearer tokens only the minimum scopes required and keep sensitive profiles inaccessible to other local users.
-
Establish a documented update process in which each new package version and its dependency changes are reviewed before changing the pinned version.
-
