T08 · Insecure Dependencies
- Location
README.md:143- Finding
Unpinned globally installed CLI creates a supply-chain execution risk
- Content
View full analysis
Vulnerability Details
File Location:
README.md:143-150; also documented inSKILL.md:150-154
Vulnerability Type: Unpinned third-party dependency with access to authentication credentials
Risk Level: MediumVulnerable Code and Instructions
markdown ### Twitter/X Setup (Optional) 1. Install bird CLI: `npm install -g @steipete/bird` 2. Login to x.com in Safari/Chrome 3. Create `.env` file:AUTH_TOKEN=your_auth_token CT0=your_ct0_token
text Technical Analysis
The installation command retrieves and globally installs the latest version of
@steipete/birdwithout an exact version, lockfile, or integrity constraint. npm installation may execute package lifecycle scripts with the privileges of the installing user. The installed program is subsequently invoked with authenticated X session credentials.The social-media integration is consistent with the declared functionality, but using an unpinned global package is not the minimum-risk implementation. The package's effective code can change after this Skill has been reviewed.
No evidence shows that the current package is malicious. The vulnerability is the avoidable trust placed in mutable registry content and its transitive dependencies.
Attack Path
- An attacker compromises the package publisher, npm account, package distribution channel, or a transitive dependency.
- A malicious release becomes the latest version associated with
@steipete/bird. - A user follows the documentation and runs
npm install -g @steipete/bird. - Malicious installation lifecycle code or runtime code executes as the user.
- When the scanner invokes the CLI, the compromised program can access the inherited environment, including X session credentials and potentially unrelated secrets.
- The attacker can exfiltrate those credentials or perform other actions available to the local user.
Impact Assessment
Successful exploitation cou ...[truncated 369 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, reviewed version rather than installing the latest release.
- Record and verify package integrity metadata and use a lockfile where possible.
- Avoid global installation. Install the package in a dedicated, isolated directory or container with minimal filesystem access.
- Document the verified upstream repository, expected package identity, review process, and secure update procedure.
- Disable package lifecycle scripts during installation where compatible with the dependency.
- Prefer an official, scoped, read-only API integration over a browser-session CLI.
- Combine dependency pinning with a minimal subprocess environment so a compromised dependency cannot access unrelated credentials.
