T08 · Insecure Dependencies
- Location
SKILL.md:26- Finding
Execution of Unpinned Third-Party npm Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 26-35
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: MediumVulnerable Code
bash # Print a production URL. npx --yes @cloudcreate/cli open image:resize --mode width --width 1200 --quality 82 --format webp --locale en --print # Open the production browser tool directly. npx --yes @cloudcreate/cli open css:minify --level aggressive --locale zh # Print a self-hosted/local URL. npx --yes @cloudcreate/cli open image:compress --quality 75 --format webp --base-url http://127.0.0.1:5173 --locale en --printTechnical Analysis
The documented commands invoke
npx --yeswith an unpinned npm package name. If the package is absent locally, npm can download and execute the version currently resolved from the configured registry. The--yesoption suppresses the normal installation confirmation.Because no audited version, integrity value, or trusted registry configuration is specified, the effective code executed can change after the skill has been reviewed. A malicious package release, compromised maintainer account, registry compromise, or compromised transitive dependency could therefore cause arbitrary package or lifecycle code to execute.
The local deployment guidance at
SKILL.md:65-70also recommends cloning an external repository and runningnpm installwithout requiring a pinned repository commit or verified dependency lockfile, expanding the same supply-chain exposure.Attack Path
- An attacker compromises
@cloudcreate/cli, one of its transitive dependencies, its publishing account, or the package distribution channel. - The attacker publishes a malicious version that remains compatible with the unversioned package reference.
- A user or agent follows the skill and runs
npx --yes @cloudcreate/cli .... - npm resolves and downloads the attacker-controlled release without interactive installa ...[truncated 1020 chars]
- An attacker compromises
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version, for example:
bash npx @cloudcreate/cli@<reviewed-version> open ... - Remove
--yeswhere practical so that package installation requires explicit user approval. - Verify package provenance, publisher identity, signatures or attestations, and registry source before execution.
- For repeatable or automated use, declare the package in a controlled project manifest, commit the lockfile, and install with
npm ci. - Run the CLI with least privilege in a sandbox or container that does not expose unrelated credentials or sensitive files.
- Pin the locally cloned application to an audited commit or signed release rather than an unspecified repository head.
- Require the repository's reviewed lockfile and use
npm ciinstead of an unconstrainednpm install. - Document expected package versions and integrity metadata so users can detect unexpected supply-chain changes.
- Pin the CLI to a specifically reviewed version, for example:
