T08 · Insecure Dependencies
- Location
README.md:9- Finding
Unpinned Remote Package Execution During Installation
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 9–13
Vulnerability Type: Unpinned third-party package and mutable remote source
Risk Level: MediumVulnerable Code
markdown ## Install ```bash npx skills add patsnap/skills/tree/main/open-platform/patent-panorama-insightstext ### Technical Analysis The installation command invokes `npx` without pinning the `skills` package to an exact, reviewed version. Depending on the local environment and cache state, `npx` may download and execute the package currently published under that name. The skill source is also identified through a mutable repository path rather than an immutable commit hash or a cryptographically verified release. Consequently, the code executed or installed later may differ from the files covered by this audit. This creates a supply-chain risk: compromise of the package registry account, package publication process, repository account, or mutable upstream branch could substitute malicious installer logic or skill content after review. No malicious package or active compromise was observed in the audited artifact; the vulnerability is the lack of version and integrity controls. ### Attack Path 1. An attacker compromises the package registry account, publication pipeline, upstream repository, or another relevant supply-chain component. 2. The attacker publishes a malicious version of `skills` or modifies content reachable through the mutable repository path. 3. A user follows the documented installation instructions. 4. `npx` retrieves the currently available package rather than a specifically reviewed version. 5. The retrieved package runs with the invoking user’s privileges and installs attacker-controlled content. 6. That content may access resources available to the user or alter the installed skill’s future behavior. ### Impact Assessment Successful exploitation could execute arbitrary code with the privileges of the user running the installation comma ...[truncated 672 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin the
skillspackage to an exact reviewed version rather than relying on the current registry release:bash npx --yes skills@<reviewed-exact-version> add <immutable-source> -
Replace the mutable repository reference with an immutable commit SHA or a signed release tag whose underlying commit is protected.
-
Publish and verify a cryptographic checksum or signature for the expected skill artifact before installation.
-
Document the expected package version, source commit, artifact digest, and verification procedure together.
-
Review the package’s lifecycle scripts and dependency tree before recommending execution. Where supported, disable lifecycle scripts during acquisition and run only explicitly reviewed installation logic.
-
Run installation with a non-privileged account in a restricted environment. Do not use
sudo, administrator privileges, or broadly exposed production credentials. -
Use an approved registry, lockfile, and dependency allowlist in managed deployments. Enable registry provenance or signature verification where available.
-
Re-audit whenever the pinned package version, source commit, or artifact digest changes.
-
