T08 · Insecure Dependencies
- Location
scripts/setup.sh:182- Finding
Unpinned npm Dependency Installation During Credentialed Setup
- Content
View full analysis
&1 | tail -3) ok "cos-nodejs-sdk-v5 installation completed" ``` The corresponding skill metadata also declares the package without an exact version: ```json { "id": "node-cos-sdk", "kind": "node", "package": "cos-nodejs-sdk-v5", "label": "Install COS Node.js SDK" } ``` ### Technical Analysis The setup script installs `cos-nodejs-sdk-v5` without an exact version, committed lockfile, or integrity constraint. npm will resolve whichever package version currently satisfies the unspecified version requirement. Default npm behavior also permits package lifecycle scripts to execute during installation. The package name appears to refer to Tencent Cloud's official SDK; the audit found no evidence that the currently referenced package is malicious. The vulnerability is nevertheless an unsafe supply-chain boundary: the effective code installed in the future can differ from the code reviewed with this skill. This is particularly sensitive because users are instructed to export Tencent Cloud credentials before running: ```bash setup.sh --from-env ``` Consequently, npm and any dependency lifecycle process launched during installation may inherit `TENCENT_COS_SECRET_ID`, `TENCENT_COS_SECRET_KEY`, and an optional STS token. ### Attack Path 1. An attacker compromises the npm account, registry distribution channel, or a transitive dependency associated with the package. 2. The attacker publishes a modified package version or dependency containing a malicious npm lifecycle script. 3. A user exports Tencent Cloud credentials as directed by the skill. 4. The user runs `scripts/setup.sh --from-env` ...[truncated 1044 chars]- Remediation
View remediation
