T08 · Insecure Dependencies
- Location
README.md:23- Finding
Unpinned Third-Party Installation Command Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
README.md:23-27
Vulnerability Type: Unpinned third-party installer and mutable remote source
Risk Level: MediumVulnerable Code
markdown ## Installation ```bash npx add https://github.com/wpank/ai/tree/main/skills/backend/architecture-patternstext ### Technical Analysis The documented installation procedure invokes `npx` without pinning the `add` package to a reviewed version. It also references content under a mutable GitHub branch path rather than an immutable commit. Consequently, the command may retrieve or execute components whose contents can change after this audit. If either the npm package resolution or upstream GitHub repository is compromised, users could receive code different from the reviewed project. This is a supply-chain weakness rather than evidence that the currently audited files are malicious. ### Attack Path 1. An attacker compromises the npm package resolved as `add`, its maintainer account, or the referenced GitHub repository. 2. The attacker publishes a malicious package release or modifies content on the mutable `main` branch. 3. A user follows the installation command from the README. 4. `npx` downloads and potentially executes the compromised package, while the installer retrieves mutable remote content. 5. Attacker-controlled code runs with the permissions of the user invoking the command. ### Impact Assessment Successful exploitation could provide arbitrary code execution under the installing user's account. The resulting scope may include access to files, environment variables, credentials, development repositories, and network resources available to that user. If the command is run by a privileged account or in a highly privileged CI environment, the impact expands accordingly. No remote payload execution, credential theft, persistence, or other malicious behavior was observed in the currently audited project con ...[truncated 6 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the package invoked by
npxto an exact, reviewed version rather than allowing implicit latest-version resolution. - Pin the GitHub source to an immutable commit SHA instead of the mutable
mainbranch. - Prefer downloading a release archive and verifying a published cryptographic checksum or signature before installation.
- Avoid executing package runners when simple, non-executable file-copy installation is sufficient.
- In CI environments, install with a minimally privileged account, restrict outbound network access, and use an approved dependency proxy or allowlist.
- Document the expected package version, source commit, and checksum so users can reproduce the audited installation.
- Pin the package invoked by
