T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Mutable npm Package Installed Globally Without Integrity Verification
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 10–11
Vulnerability Type: Unpinned global dependency installation
Risk Level: HighVulnerable Code
yaml setup: | npm install -g @jackwener/opencli@latestThe same mutable installation command is also repeated in the installation instructions at line 25.
Technical Analysis
The skill instructs users to install the
@jackwener/openclinpm package globally through the mutablelatestdistribution tag. Although the metadata elsewhere identifies an installed version,1.5.9, the actual installation command does not pin that version or verify a package digest or signature.npm packages may execute lifecycle scripts during installation. Because this package is installed globally, a future package release—or a release published after compromise of the package publisher or registry account—could run attacker-controlled code with the privileges of the user performing the installation. The effective code installed by this instruction can therefore change after the skill has been audited.
No malicious package content is included in the reviewed project, and the audit does not establish that the named package is currently malicious. The vulnerability is the unsafe, mutable dependency acquisition process.
Attack Path
- An attacker compromises the npm publisher account, package release process, or another relevant supply-chain component.
- The attacker publishes a malicious package version under the
latestdistribution tag. - A user follows the skill instructions and runs
npm install -g @jackwener/opencli@latest. - npm retrieves the attacker-controlled release.
- Malicious lifecycle scripts or package code execute with the installing user's privileges.
- The installed global CLI can subsequently access local files, invoke other programs, or abuse browser-connected capabilities when the user runs it.
Impact Assessment
...[truncated 487 chars]
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed version, such as@jackwener/opencli@1.5.9, after independently validating that release. - Publish and verify a cryptographic digest or signed provenance for the expected package artifact.
- Document the canonical npm registry, package scope, publisher identity, and release source.
- Avoid elevated privileges during installation and prefer a project-local or isolated installation over a global one.
- Disable npm lifecycle scripts during initial acquisition where operationally possible, then explicitly review any required scripts before enabling them.
- Use lockfiles, trusted registries, dependency monitoring, and reproducible release procedures.
- Ensure every installation example uses the same pinned and verified version.
- Replace
