T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Unpinned Third-Party Packages Create a Mutable Supply-Chain Execution Path
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:26,SKILL.md:44,SKILL.md:60; also repeated inREADME.md:18,README.md:32,README.md:110, andexamples/quickstart.md:8
Vulnerability Type: Unpinned executable dependency
Risk Level: MediumVulnerable Code
bash npm install -g @swarmrecall/clibash npm install @swarmrecall/sdkThe update instructions explicitly select the latest available release:
bash npm install -g @swarmrecall/cli@latestTechnical Analysis
The Skill instructs users to retrieve and execute third-party npm packages without pinning an exact reviewed version or providing an integrity hash. The project contains documentation only and does not include the CLI or SDK source, a package lockfile, or another mechanism that binds installation to the code reviewed during this audit.
npm installations may execute package lifecycle scripts. A future compromised or malicious release could therefore run code during installation with the privileges of the user invoking npm. Global installation of the CLI also makes the executable available throughout the user's environment and increases the scope of a compromised package.
There is no evidence in the audited project that the named packages are currently malicious. The vulnerability is that the effective installed code can change independently after this Skill has been reviewed.
Attack Path
- An attacker compromises the npm publisher account, package release process, or a transitive dependency.
- The attacker publishes a malicious version under the existing package name.
- A user follows the documented unversioned installation or
@latestupdate command. - npm downloads the compromised package and may execute its lifecycle scripts.
- Malicious code runs with the installing user's privileges and can access files, environment variables, agent configuration, and network resources available to tha ...[truncated 389 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI and SDK to exact versions that have been reviewed, rather than using an unqualified package name or
@latest. - Publish and verify package integrity hashes or signed release provenance.
- For SDK projects, provide a lockfile and require reproducible installation with
npm ci. - Prefer a project-local CLI installation over global installation where practical.
- Disable npm lifecycle scripts when they are not required, or document and audit every required lifecycle script.
- Add an upgrade procedure that reviews source changes and dependencies before changing the pinned version.
- Run the CLI under a dedicated, least-privileged account or sandbox without unrelated credentials.
- Pin the CLI and SDK to exact versions that have been reviewed, rather than using an unqualified package name or
