T08 · Insecure Dependencies
- Location
scripts/dytext.sh:7- Finding
Unpinned npm Package Is Downloaded and Executed at Runtime
- Content
View full analysis
Vulnerability Details
File Location:
scripts/dytext.sh:7
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
bash #!/bin/bash # dytext.sh - Videosays compatible Skill script # Invokes videosays through npx and handles registration, login, and transcription set -e exec npx videosays "$@"Related unpinned commands also appear in
SKILL.md:25andSKILL.md:31-41:bash npx videosays setup npx videosays transcribe "https://v.douyin.com/xxxxx/" npx videosays transcribe "6.44 ... https://v.douyin.com/xxxxx/" zh-CN npx videosays balance npx videosays historyTechnical Analysis
The wrapper executes
npx videosayswithout specifying an exact package version. The project contains no lockfile, integrity hash, vendored dependency, or locally reviewed installation that fixes the executable to a known artifact. If the package is not already available locally,npxcan retrieve executable code from the npm registry at invocation time.Consequently, the code executed by the Skill can change after this repository has been audited. A compromised package release, npm maintainer account, or upstream supply-chain component could introduce arbitrary lifecycle or command-line code. The quoted
"$@"expansion does not itself create shell injection; the weakness is the mutable executable dependency to which all arguments are delegated.Attack Path
- An attacker compromises the
videosaysnpm package, its maintainer account, or another part of its publication pipeline. - The attacker publishes a malicious version under the package’s legitimate name.
- A user or Agent invokes
scripts/dytext.sh, or follows one of the documentednpx videosayscommands. - Because no exact version or integrity value is enforced,
npxresolves and may download the affected package version. - The malicious package code executes with the permis ...[truncated 877 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Pin
videosaysto a specific, reviewed version rather than resolving the latest available release:bash npx --yes videosays@1.2.3 "$@"Replace the example version with an audited release. Version pinning reduces unintended updates but does not independently verify package integrity.
-
Prefer declaring the package in a
package.json, committing a lockfile with registry integrity metadata, and installing dependencies during a controlled setup phase:bash npm ci --ignore-scriptsReview whether the dependency legitimately requires installation scripts before allowing them.
-
Invoke only the locally installed, locked executable at runtime, such as:
bash exec npx --no-install videosays "$@"This prevents runtime package retrieval when the expected dependency is absent.
-
Review package contents, transitive dependencies, lifecycle scripts, publisher history, and checksums before approving upgrades. Automate dependency alerts while keeping updates subject to review.
-
Run the Skill with least privilege in a sandbox or container. Restrict filesystem access, environment variables, credential exposure, and outbound network destinations to those required for transcription.
-
Update every command in
SKILL.mdandREADME.mdto use the same controlled installation and pinned execution process so users do not bypass the hardened wrapper.
-
