T08 · Insecure Dependencies
- Location
README.md:26- Finding
Unpinned Executable Dependencies and Mutable Remote Resources
- Content
View full analysis
Vulnerability Details
File Location:
README.md:26,README.md:32,SKILL.md:23,SKILL.md:179, andreferences/advanced-features.md:516
Vulnerability Type: Supply-chain exposure through unpinned packages and remotely hosted executable JavaScript
Risk Level: MediumVulnerable Code
README.md:26bash npx add https://github.com/wpank/ai/tree/main/skills/writing/mermaid-diagramsREADME.md:32bash npx clawhub@latest install mermaid-diagramsSKILL.md:23bash npx clawhub@latest install mermaid-diagramsSKILL.md:179markdown - Mermaid CLI — `npm install -g @mermaid-js/mermaid-cli` then `mmdc -i input.mmd -o output.png`references/advanced-features.md:516javascript import mermaid from 'https://cdn.jsdelivr.net/npm/mermaid@10/dist/mermaid.esm.min.mjs';Technical Analysis
The documented installation commands resolve and execute third-party packages without pinning them to immutable versions or verified artifacts:
npx clawhub@latestexplicitly selects a mutable release tag.npm install -g @mermaid-js/mermaid-clidoes not specify an exact package version and installs the resolved package globally.- The GitHub installation URL points to a mutable branch path rather than an immutable commit.
npx add ...may resolve and execute a package namedadd, creating additional ambiguity over which installer is trusted.- The CDN import uses the broad
@10major-version selector without an integrity hash. The JavaScript returned for the same documented URL can consequently change after review.
Package-manager installation hooks and
npxcommands can execute code during dependency resolution and installation. If a registry account, dependency, mutable branch, CDN response, or release process is compromised, the effective code executed by users can differ from the content that was audited.The CDN example ...[truncated 2052 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin every npm package to an exact audited version rather than using
@latestor omitting the version:bash npx clawhub@<exact-version> install mermaid-diagrams npm install --save-dev @mermaid-js/mermaid-cli@<exact-version> -
Replace the mutable GitHub branch URL with an immutable commit reference. Document the expected commit hash and verify downloaded content before installation.
-
Replace the ambiguous
npx addcommand with an installation method whose package identity, publisher, version, and behavior are explicitly documented and verified. -
Prefer a project-local Mermaid CLI dependency over a global installation. Commit the relevant lockfile and use deterministic installation commands such as
npm ci. -
Review package provenance, signatures, lifecycle scripts, and transitive dependencies before recommending installation. Where supported, enforce registry integrity metadata and trusted publisher policies.
-
Pin the CDN import to an exact Mermaid release rather than
@10. Prefer serving a reviewed local copy. If a compatible loading mechanism is used, enforce Subresource Integrity and an appropriately restrictive Content Security Policy. -
Run package installation and diagram rendering under a non-administrative account or isolated container with only the minimum required filesystem and network access.
-
Periodically review pinned versions for security updates and update them through a controlled process that includes dependency auditing and integrity verification.
-
