T08 · Insecure Dependencies
- Location
SKILL.md:83- Finding
Unsafe Installation and Execution of Untrusted Project Dependencies
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 83–84
Vulnerability Type: Untrusted dependency lifecycle and project-script execution
Risk Level: HighComplete Code Snippet:
bash npm install npm run buildTechnical Analysis
The skill instructs the agent to run
npm installandnpm run buildautomatically when a framework project has no existing build directory.npm installcan execute lifecycle scripts supplied by dependencies, includingpreinstall,install, andpostinstall. The instruction does not require a trusted lockfile, dependency-source validation, lifecycle-script suppression, or review of dependency changes. Consequently, a malicious package introduced through a compromised dependency, dependency confusion, typosquatting, or an attacker-controlled project can execute code during installation.In addition,
npm run buildexecutes the target repository's package-defined build command. An attacker controllingpackage.jsoncan replace the expected frontend build operation with arbitrary shell commands. No sandboxing, command review, least-privilege restriction, or explicit user confirmation is required before execution.Attack Path
- An attacker supplies or modifies a frontend project containing either:
- a dependency with a malicious installation lifecycle script; or
- a malicious
buildentry inpackage.json.
- The user invokes the deployment skill for that project.
- The skill detects
package.jsonand the absence of a prebuiltdist/orbuild/directory. - Following the documented workflow, the agent executes
npm install. - The package manager runs attacker-controlled dependency lifecycle code, if present.
- The agent then executes
npm run build, which can invoke an attacker-controlled shell command. - The malicious process runs with the privileges and accessible environment of the agent process.
Impact Assessment
...[truncated 699 chars]
- An attacker supplies or modifies a frontend project containing either:
- Remediation
View remediation
Remediation Suggestions
- Require explicit user approval before installing dependencies or executing project-defined scripts.
- Inspect and display the relevant
package.jsonscripts before running them. - Require a committed lockfile and use the corresponding deterministic installer, such as:
bash npm ci --ignore-scripts - Validate dependency registry sources and reject unexpected Git URLs, local paths, untrusted registries, and lockfile inconsistencies.
- Audit dependencies before allowing lifecycle scripts. Enable only specifically reviewed scripts when they are essential.
- Execute installation and build operations in an ephemeral, unprivileged container or sandbox with:
- read-only access to source files where possible;
- a dedicated writable build-output directory;
- no host credential directories;
- restricted network access;
- resource and execution-time limits.
- Remove
PINATA_API_KEY,PINATA_SECRET_KEY, and other deployment secrets from the build environment. Inject them only into the separate upload step after the build completes successfully. - Review produced artifacts before upload and ensure the build process cannot modify files outside its isolated workspace.
