T08 · Insecure Dependencies
- Location
README.md:12- Finding
Unpinned Package Execution and Mutable Skill Source
- Content
View full analysis
Vulnerability Details
File Location:
README.md:12
Vulnerability Type: Supply-chain risk caused by an unpinned executable package and mutable upstream source
Risk Level: MediumVulnerable Code Snippet:
bash npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insights-searchTechnical Analysis
The installation command invokes the
skillsnpm package throughnpxwithout specifying a verified version or integrity constraint. Depending on the local environment and cache state,npxmay download and execute the latest available version of that package.The skill is also selected from the mutable GitHub
mainbranch rather than an immutable commit. Consequently, the executable installer and installed skill content can differ from the versions that were previously reviewed. This creates a time-of-check/time-of-use supply-chain gap.Exploitation requires compromise of a relevant upstream distribution channel, such as the npm package, package publisher account, source repository, or branch. There is no evidence in the audited files that these upstream sources are currently compromised.
Attack Path
- An attacker compromises the
skillsnpm package, its publisher account, or the referenced upstream repository. - The attacker publishes a malicious package version or modifies content reachable through the
mainbranch. - A user follows the documented installation command.
npxresolves and executes the unpinned package, which retrieves the mutable upstream skill.- Malicious installer logic may execute with the invoking user's privileges, or altered skill instructions may be installed into the Agent environment.
- The resulting code or instructions may access data and tools available to that user or Agent.
Impact Assessment
Successful exploitation could execute attacker-controlled installation logic with the privileges of the user running
npx. The affe ...[truncated 509 chars]- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsnpm CLI to a specific, reviewed version instead of allowingnpxto resolve the latest release. - Reference the skill source using an immutable Git commit rather than the mutable
mainbranch. - Verify package provenance, publisher identity, signatures, and integrity hashes before execution.
- Use a lockfile or an internally approved package mirror where the installation workflow supports it.
- Run installation with an unprivileged account in a restricted environment, without unnecessary credentials or sensitive environment variables.
- Document the expected package version, source commit, and file checksums so users can verify installed artifacts.
- Add automated dependency and provenance checks to detect unexpected changes in the npm package or upstream skill files.
- Pin the
