T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned npm Package Is Downloaded and Executed
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 18-24 and 27-29
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumThe skill declares the mutable
constants-skillsnpm package without an exact version and instructs users to execute it throughnpx.yaml install: - id: npm kind: npm package: constants-skills bins: - constants-skills label: Install constants-skills (npm)bash npx constants-skills install linkedin_ai_roast_generator_0edc9796Technical Analysis
No exact package version, lockfile, package integrity hash, or locally auditable implementation is supplied. Consequently, the reviewed documentation does not uniquely identify the code that will be installed and executed. By default,
npxcan download the package version resolved from the npm registry and immediately run its executable.This creates a supply-chain trust boundary in which the effective executable may change after this skill has been reviewed. A compromised npm publisher account, malicious package release, compromised transitive dependency, or registry-level substitution could cause the documented command to execute attacker-controlled code.
The project contains only
SKILL.md; therefore, the behavior of the installed CLI and hosted skill implementation cannot be verified from the audited artifact.Attack Path
- An attacker compromises the
constants-skillspublishing account, its build pipeline, or one of its dependencies. - The attacker publishes a malicious version that is eligible for default npm resolution.
- A user follows the documented command:
bash npx constants-skills install linkedin_ai_roast_generator_0edc9796 npxretrieves and executes the compromised package under the user's account.- The malicious process accesses data available to that account, potentially including
CONSTANTS_API_KEY...[truncated 824 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
constants-skillsto an exact, reviewed version in both the installation metadata and command:yaml package: constants-skills@X.Y.Zbash npx --yes constants-skills@X.Y.Z install linkedin_ai_roast_generator_0edc9796 - Maintain a lockfile with npm integrity metadata and perform installation with
npm ciwhere practical. - Verify the package tarball against a trusted cryptographic digest or signed provenance before execution.
- Publish or vendor the relevant implementation so reviewers can inspect the code that processes profile data and credentials.
- Audit direct and transitive dependencies with supply-chain scanning and promptly address compromised or vulnerable components.
- Run installation and invocation in a restricted environment with minimal filesystem access, constrained outbound networking, and only the required API credential.
- Use a narrowly scoped, revocable API key and rotate it immediately if package compromise is suspected.
- Pin
