T03 · Remote Payload Retrieval and Execution
- Location
sources.md:45- Finding
Routine searches execute unpinned remote npm packages
- Content
View full analysis
" npx skills find "" npx -y @lobehub/market-cli skills search --q "" ``` ### Technical Analysis The Skill instructs the Agent to invoke multiple npm packages through `npx` as part of an ordinary search. No exact package versions, integrity hashes, lockfiles, or immutable releases are specified. When a package is unavailable locally, `npx` can retrieve and execute it from the configured npm registry. The effective code therefore remains mutable after this Skill has been reviewed. The LobeHub command also uses `-y`, suppressing the normal package-execution confirmation. This code execution happens during discovery, before the user selects or approves installation of a recommended Skill. The conservative installation policy therefore does not protect against malicious code in the search CLI itself. ### Attack Path 1. An attacker compromises one of the referenced npm packages, its publisher account, or a transitive dependency. 2. The Skill activates, potentially through its broad implicit activation rules. 3. The Agent runs an unpinned `npx` search command. 4. `npx` downloads the current package version and dependencies. 5. Malicious package initialization or runtime code executes with the Agent process's operating-system permissions. 6. The payload can access resources available to that process or modify files writable by the user. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the Agent user's account. The accessible scope may include user files, Agent configuration, environment variables, authentication material exposed to the process, and writable Skill directories. No direct privilege escalation to root is de ...[truncated 88 chars]- Remediation
View remediation
