T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Global npm Package Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 11
Vulnerability Type: Unpinned third-party dependency installed globally
Risk Level: Mediumbash npm install -g firecrawl-cliTechnical Analysis
The skill instructs users or agents to install
firecrawl-clifrom the npm registry without specifying an exact version or validating an integrity hash. Consequently, the package content installed at execution time may differ from the version reviewed during this audit.npm packages may execute lifecycle scripts during installation. Because the command installs the package globally, such scripts execute with the installing user's privileges and can affect globally available tooling. The project provides no lockfile, package integrity value, vendored source, or reviewed version constraint that would make the dependency reproducible.
This finding does not establish that the current
firecrawl-clipackage is malicious. The vulnerability is the unsafe, non-reproducible dependency installation pattern and its exposure to package-registry or maintainer compromise.Attack Path
- An attacker compromises the npm package, its maintainer account, or its publishing pipeline.
- The attacker publishes a malicious or backdoored version under the existing package name.
- A user or agent follows the documented unpinned installation command.
- npm downloads the current package version rather than a previously reviewed version.
- Malicious package code or an installation lifecycle script executes with the installing user's privileges.
- The compromised globally installed CLI can subsequently intercept credentials, alter command results, or execute additional code whenever invoked.
Impact Assessment
Successful exploitation could execute arbitrary code with the privileges of the account running npm. Potential effects include theft of environment variables and Firecrawl credentials, modification of u ...[truncated 432 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin
firecrawl-clito an exact, reviewed version rather than installing the latest available release. - Record and verify the expected package integrity hash.
- Prefer a project-local dependency over a global installation to reduce system-wide impact.
- Commit a lockfile and use a reproducible installation mechanism such as
npm ci. - Disable npm lifecycle scripts during installation when they are not required, for example by using
--ignore-scripts. - If lifecycle scripts are necessary, review them and the package's transitive dependencies before installation.
- Establish a controlled process for reviewing and updating the pinned version.
- Pin
