T08 · Insecure Dependencies
- Location
setup.sh:12- Finding
Unpinned Global npm Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
setup.sh, lines 12-16
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: MediumVulnerable Code:
bash if ! command -v mcporter >/dev/null 2>&1; then echo "mcporter not found. Installing mcporter..." npm install -g mcporter echo "mcporter installed." fiTechnical Analysis
The setup script installs the latest version of the
mcporternpm package without pinning a reviewed version or verifying package integrity. npm packages can execute lifecycle scripts during installation. Consequently, the effective code executed by this setup process may change after the skill has been audited.The global installation option,
-g, also modifies the invoking user's global npm environment rather than isolating the dependency within the project. If the package, one of its transitive dependencies, or the registry delivery path is compromised, arbitrary package lifecycle code could execute with the permissions of the user runningsetup.sh.Attack Path
- An attacker compromises the
mcporternpm package, one of its transitive dependencies, or the associated package publication account. - The attacker publishes a malicious version containing an installation lifecycle script or modified executable code.
- A user without an existing
mcportercommand runsbash setup.sh. npm install -g mcporterretrieves the current unpinned release and executes any applicable lifecycle scripts.- The malicious code runs with the operating-system privileges of the invoking user and modifies the global npm environment.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the user running the setup script. It could access files and credentials available to that user, alter globally installed npm tools, or modify user-level configuration. If the script is run from an elevated ...[truncated 206 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin
mcporterto a specifically reviewed version rather than installing the latest release implicitly. - Verify package provenance and integrity using an approved lockfile, registry policy, or cryptographic integrity metadata.
- Prefer a project-local dependency over
npm install -gto reduce the scope of filesystem and environment modifications. - Disable npm lifecycle scripts where compatible with the package and deployment process.
- Require explicit user approval before installing software, and document the exact package version and source.
- Execute installation with the least-privileged account required and avoid running the setup script as root or through
sudo.
- Pin
