T08 · Insecure Dependencies
- Location
SKILL.md:35- Finding
Unpinned Global npm Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 35-39
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumVulnerable Code
markdown ## Installation ```bash npm install -g mineru-open-apitext ### Technical Analysis The installation instructions require users to install `mineru-open-api` globally from the npm registry without specifying a reviewed version, integrity hash, lockfile, or verified source repository. Consequently, the package content retrieved during installation can change after the Skill has been audited. npm packages can define lifecycle scripts that execute during installation with the privileges of the invoking user. The global `-g` installation also places the executable in a shared command search path, increasing its reach beyond a single project. Although the audited file does not demonstrate that the current package is malicious, this installation method creates an avoidable supply-chain exposure. ### Attack Path 1. An attacker compromises the npm package, its maintainer account, or the package publication process. 2. The attacker publishes a malicious version under the expected package name. 3. A user follows the Skill instructions and runs `npm install -g mineru-open-api`. 4. npm retrieves the latest available package rather than a specifically reviewed release. 5. Malicious lifecycle code can execute during installation under the user's privileges. 6. The globally installed CLI can subsequently execute attacker-controlled behavior whenever the Skill invokes `mineru-open-api`. ### Impact Assessment Successful exploitation could permit arbitrary code execution with the privileges of the user performing the installation. Potential consequences include access to files and credentials available to that account, modification of user-owned data, malicious document processing, and replacement or misuse of the globally available CLI. Administrative impact would be pos ...[truncated 133 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the dependency to a specific, reviewed version rather than installing the latest release implicitly.
- Document the authoritative npm package and source-code repository so users can verify package provenance.
- Provide an integrity verification mechanism, such as a trusted checksum or lockfile generated from the reviewed release.
- Prefer a project-local installation over
npm install -gto reduce system-wide exposure and improve dependency isolation. - Consider invoking the pinned local executable through an appropriate package script.
- Disable npm lifecycle scripts with
--ignore-scriptswhere the package can function without them. - Review the selected package version, including its transitive dependencies and lifecycle scripts, before recommending it.
- Explicitly warn users not to run the installation with administrative privileges.
