T08 · Insecure Dependencies
- Location
SKILL.md:70- Finding
Mutable npm Dependency Installed Globally
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:19andSKILL.md:70
Vulnerability Type: Unpinned third-party dependency and unsafe global installation
Risk Level: MediumComplete Code Snippets
yaml install: - kind: node package: omniwire@latest bins: ["omniwire", "ow"]bash npm install -g omniwire@latestTechnical Analysis
The Skill directs the agent to globally install
omniwire@latest. Thelatestdistribution tag is mutable, so the installed artifact can change after this Skill has been reviewed. Neither an exact package version nor an integrity hash is specified.npm installation may execute package lifecycle scripts. A global installation gives the package access under the privileges of the user running npm and places executable files in a shared command path. The actual npm package is not included in the audited project, which contains only
SKILL.md; consequently, its implementation and lifecycle scripts could not be verified.This is a supply-chain weakness rather than evidence that the current OmniWire release is malicious.
Attack Path
- An attacker compromises the npm publisher account, package publication process, or a future release assigned to the
latesttag. - The attacker publishes a modified package containing a malicious lifecycle script or executable.
- An agent follows the Skill and runs
npm install -g omniwire@latest. - npm retrieves the attacker-controlled release and may execute its lifecycle scripts during installation.
- The malicious package executes with the installing user's privileges and can persist executable content in globally accessible npm locations.
- Subsequent invocations of
omniwireorowexecute the compromised implementation.
Impact Assessment
Successful exploitation could provide arbitrary code execution with the privileges of the account performing the installation. Potential impact incl ...[truncated 647 chars]
- An attacker compromises the npm publisher account, package publication process, or a future release assigned to the
- Remediation
View remediation
Remediation Suggestions
- Replace
omniwire@latestwith an exact, reviewed version in both the metadata and installation command, for exampleomniwire@3.5.0. - Verify the package archive against a trusted integrity digest or signed provenance before installation.
- Inspect package contents and lifecycle scripts before approving a new version.
- Initially install with lifecycle scripts disabled, where operationally feasible, and explicitly review any scripts required for functionality.
- Avoid global installation where possible. Run the package from an isolated environment, dedicated container, or restricted service account.
- Apply least privilege to the installation account and keep administrative SSH credentials unavailable to the package unless required for an explicitly approved operation.
- Establish a controlled upgrade process that reviews and pins each new release instead of automatically following the mutable
latesttag.
- Replace
