T08 · Insecure Dependencies
- Location
scripts/dytext.sh:7- Finding
Unpinned npm Package Is Retrieved and Executed Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-aligned, but it runs an unpinned npm package at runtime while handling API keys and video links.
Install only if you are comfortable trusting the live Videosays npm package and service. Prefer a pinned, reviewed version or lockfile-managed local install, and run it in a least-privileged environment because the setup/transcription flow handles an API key, stores it under `~/.videosays`, and sends video links plus the key to Videosays.
scripts/dytext.sh:7Unpinned npm Package Is Retrieved and Executed Through npx
The README instructs users to run npx videosays setup without pinning a specific package version. Because npx resolves and executes the latest published package by default, a compromised maintainer account, malicious new release, or dependency hijack could result in arbitrary code execution on the user's machine. In this skill's context, the command is part of first-time setup and handles API key onboarding, which increases sensitivity and makes the unpinned execution path more dangerous.
The skill documentation tells users to execute npx videosays without version pinning, which causes retrieval and execution of whatever version is current on the npm registry at runtime. If the npm package or its supply chain is compromised, this becomes a direct arbitrary code execution vector. Since this skill is specifically guiding users to run the command on shared workstation environments used for agent tooling, the risk is elevated beyond a purely informational mention.
This README example uses npx videosays transcribe without specifying an exact version, exposing users to execution of unreviewed future package contents. npx is effectively a remote code execution mechanism when used this way, and compromise of the package publisher or dependencies could lead to malware execution, credential theft, or local data access. The context is more dangerous because the tool processes user-supplied links and may run in environments with access to agent workspace data and stored secrets.
The command example relies on unpinned npx videosays, which can silently execute a newly published package version. That creates a supply-chain execution risk: an attacker controlling the package or a dependency could run arbitrary code under the user's privileges. Because the command is presented as normal usage rather than an explicitly reviewed install step, users are likely to copy-paste it without scrutiny.
The README documents npx videosays balance without a pinned version, meaning the latest registry version will be fetched and executed at runtime. While the balance command may seem low-risk functionally, the underlying execution risk is the same: arbitrary code from a compromised package could access local files, environment variables, or tokens. The impact is somewhat lower than setup because it is less directly tied to credential onboarding, but still constitutes a real supply-chain vulnerability.
The history example invokes npx videosays history 20 without pinning the package version, which exposes users to execution of arbitrary future package contents. Any supply-chain compromise could abuse the command invocation to harvest local credentials or modify files. Although the business function is only reading history, the security boundary is the package execution itself, not the advertised subcommand.
The architecture section references npx videosays as the execution mechanism without noting version pinning or other safeguards. This normalizes runtime execution of the latest npm package and obscures the supply-chain trust assumption from users. In the context of an agent skill that may be adopted by non-expert users, that omission increases the likelihood of unsafe copy-paste use.
The skill declares a dependency on npx, which fetches and executes packages at runtime without pinning an exact package version or integrity hash. This creates a supply-chain risk: a compromised upstream package, malicious new release, or dependency confusion event could cause arbitrary code execution in the agent environment.
The command npx videosays executes an npm package without pinning a specific version, so the skill will typically resolve the latest published release at runtime. In this skill, that package handles API keys and user-supplied video links, so a malicious or compromised upstream release could exfiltrate secrets or execute arbitrary code.
npx videosays setup pulls and runs the package at runtime without version pinning, which is especially risky because the setup flow stores credentials in ~/.videosays. If the upstream package or one of its dependencies is compromised, the setup step could steal API keys or modify local configuration maliciously.
The unpinned npx videosays transcribe command introduces runtime supply-chain exposure and processes user-controlled input. Because the tool sends API keys and video links to a remote service, a malicious update could capture credentials, alter outputs, or execute arbitrary local actions before or after contacting the API.
This transcribe example again relies on npx videosays without a pinned version, allowing whatever package version npm resolves at execution time to run in the agent context. Given that the command accepts arbitrary pasted content and likely parses URLs, any malicious upstream update would have access to user input, local environment data, and network egress.
npx videosays balance still executes unpinned code from npm at runtime. Even though this subcommand is less sensitive than transcription, it can still access local credentials and environment state, so a compromised release could leak API keys or perform arbitrary actions.
The npx videosays history command is also unpinned and therefore subject to the same runtime package substitution risk as the other commands. A malicious package version could read transcription history, harvest stored API keys, and exfiltrate account metadata.
The documentation explicitly states that the skill uses npx videosays to send API keys and video links to a third-party API, but the package doing so is not pinned to a specific version. That combination increases the danger: a supply-chain compromise would expose both sensitive credentials and user content to arbitrary malicious code executed locally before the network request is even made.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
exec npx videosays "$@" executes a package by name without pinning a specific version, which can cause the script to fetch and run whatever version npx resolves at runtime. If the upstream package is compromised, a malicious version is published, or dependency resolution is tampered with, this skill could execute attacker-controlled code on the host. The skill context makes this more dangerous because the script is a thin wrapper whose entire trust boundary depends on the external package.
No suspicious patterns detected.