T08 · Insecure Dependencies
- Location
SKILL.md:281- Finding
Unpinned npm Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does design-document generation as advertised, but it should be reviewed because it repeatedly recommends running an unpinned npm CLI and mandates a third-party font mirror.
Review before installing. If used, pin `@google/design.md` to an exact reviewed version or run it from a lockfile-managed dependency, avoid running `npx` with production credentials available, treat fetched websites as untrusted input, and replace the mandatory font mirror with local fonts or a user-approved CDN.
SKILL.md:281Unpinned npm Package Execution Through npx
SKILL.md:181Mandatory Loading of Fonts From a Non-Official Third-Party CDN
SKILL.md:26Untrusted Website Content Is Processed Without Prompt-Injection Boundaries
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
**注意事项**
- `--format tailwind` 是 `json-tailwind` 的兼容别名。
- **Windows/PowerShell**:`design.md` 这个 bin 名的 `.md` 后缀会与 Windows 的 Markdown 文件关联冲突,导致 `npx @google/design.md` 无输出。改用无点的 `designmd` 别名:`npx -p @google/design.md designmd lint DESIGN.md`。
- **`npm error ENOVERSIONS`**:说明 npm 未查询公共 registry(`.npmrc` 自定义了 registry 或公司镜像未同步该包)。用 `npm config get registry` 检查,正常应为 `https://registry.npmjs.org/`。
**Lint 规则说明**(共 9 条规则)
The README instructs users to run npx @google/design.md without pinning an exact package version, which causes execution of whatever version is current at install time. If the upstream package is compromised, a malicious version is published, or a breaking update lands, users of the skill could execute unreviewed code locally during validation/export steps.
This command again relies on npx to fetch and execute @google/design.md without a pinned version. In a skill context, README commands are likely to be copied verbatim by users, so this creates a software supply-chain risk and reduces reproducibility of the generated outputs.
The unpinned npx invocation executes the latest available package code at runtime, which is unsafe for security-sensitive environments and can change behavior unexpectedly. Because the skill encourages direct use of these commands for document export, any compromise in the dependency path would directly affect users' machines or CI jobs.
This is another case of runtime package execution via npx without version pinning, exposing users to upstream package takeover, typo-supply-chain substitution, or accidental breaking changes. The risk is amplified by the fact that README usage examples often become automation snippets in CI/CD.
The npx -p @google/design.md syntax explicitly installs and runs a package on demand without pinning a version, which creates the same supply-chain and reproducibility risk as the other findings. In user-facing skill documentation, this is dangerous because it encourages immediate execution of remote code from the registry.
The npx -p @google/design.md syntax explicitly installs and runs a package on demand without pinning a version, which creates the same supply-chain and reproducibility risk as the other findings. In user-facing skill documentation, this is dangerous because it encourages immediate execution of remote code from the registry.
The text states that Google Fonts 'must' use domestic mirrors and hard-codes replacements to loli.net domains. This imposes a specific network/locale policy on all users without opt-in or an explicit region-specific justification, which matches the language/locale policy violation category.
The trigger description is broad and matches common natural-language requests such as analyzing a page or extracting design style. Over-broad triggers can cause the skill to activate unexpectedly in unrelated contexts, increasing the chance it will fetch external URLs, read local files, or steer an agent into unintended actions.
The skill instructs use of npx @google/design.md without pinning an exact package version. This allows future upstream package changes or a compromised newly-published version to alter behavior at execution time, creating a supply-chain risk whenever users follow the instructions.
This invocation also uses an unpinned npx package reference. Because npx fetches and runs code from the registry, leaving the version unconstrained exposes users to unexpected or malicious upstream updates.
The skill mandates replacing Google Fonts hosts with a specific third-party mirror without user choice or security justification. This can leak request metadata to an unvetted external service, alter font assets unexpectedly, and create compliance or trust issues in environments that require approved dependencies.
The lint command references @google/design.md without a fixed version, so the command may execute different code over time. In a skill that encourages users to run validation commands, this is a practical supply-chain exposure rather than a purely theoretical issue.
The diff command again uses an unpinned remote package through npx. If the package is compromised or behavior changes incompatibly, users following the skill may execute attacker-controlled code or receive manipulated output.
This export example relies on unversioned execution of a registry package. Because the skill explicitly instructs users to run the command, the lack of pinning materially increases supply-chain risk.
This Tailwind v4 export command uses npx with no exact version, making the generated output and executed code dependent on the current registry state. That creates avoidable integrity and execution risk.
The DTCG export example invokes an unpinned package from npm. Any malicious or breaking update upstream could affect users who follow the skill instructions and run the command.
The spec command still fetches and runs the package without version pinning. Even informational commands can execute arbitrary package code, so this remains a supply-chain concern.
The npx -p @google/design.md designmd ... form also pulls an unpinned package from the registry. Using -p does not reduce the supply-chain risk; it still executes whatever version resolves at runtime.
The npx -p @google/design.md designmd ... form also pulls an unpinned package from the registry. Using -p does not reduce the supply-chain risk; it still executes whatever version resolves at runtime.
The template instructs users to run npx @google/design.md lint DESIGN.md without pinning an exact package version. This causes execution of whatever version is current at install time, which can introduce supply-chain risk if a malicious or compromised release is published, and the risk is elevated because the file is documentation that may be copied and executed directly by users.
No suspicious patterns detected.