T08 · Insecure Dependencies
- Location
SKILL.md:18- Finding
Unpinned Global Installation of a Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18–22
Vulnerability Type: Supply-chain risk from an unpinned global dependency
Risk Level: MediumVulnerable Code:
markdown If not installed, install globally: ```bash npm install -g atifacttext ### Technical Analysis The skill instructs users to install `atifact` globally from the npm registry without specifying a reviewed version or package integrity value. Consequently, the installed package is whichever release the registry resolves at execution time, and its contents may differ from those present when the skill was audited. npm packages may execute lifecycle scripts during installation with the invoking user's privileges. A compromised publisher account, malicious new release, or registry-level supply-chain incident could therefore cause arbitrary code to run during installation. Global installation also places the CLI in a broadly accessible executable location, increasing the scope and duration of the affected tool installation. The project provides no lockfile, checksum, vendored implementation, publisher verification procedure, or source-review requirement to establish the installed artifact's provenance and integrity. ### Attack Path 1. An attacker compromises the package publisher, publishing pipeline, or another relevant supply-chain component. 2. The attacker publishes a malicious `atifact` release containing a harmful lifecycle script or altered CLI implementation. 3. A user follows the skill's instruction and runs `npm install -g atifact`. 4. npm resolves the unpinned package to the malicious release. 5. A lifecycle script may execute immediately with the user's privileges, or the malicious behavior may execute when the CLI is subsequently invoked. 6. The compromised CLI can access files and resources available to that user, including the HAR or JSONL session logs supplied for conversion. ### Impact Assessment S ...[truncated 677 chars]- Remediation
View remediation
Remediation Suggestions
- Pin
atifactto a specifically reviewed version rather than resolving the latest release:bash npm install --global atifact@<reviewed-version> - Prefer a project-local dependency recorded in
package.jsonand locked withpackage-lock.json; install it reproducibly withnpm ci. - Verify the package's registry, publisher, source repository, signatures or provenance attestations, and integrity metadata before installation.
- Review the package and its transitive dependencies for lifecycle scripts. Use
--ignore-scriptswhere compatible with the package's legitimate installation requirements. - Run the converter in a restricted environment with access only to required input and output paths, particularly when processing sensitive session records.
- Document the expected package version and a controlled upgrade-review procedure so dependency updates do not silently change the audited behavior.
- Pin
