T08 · Insecure Dependencies
- Location
SKILL.md:102- Finding
Unverifiable and Unpinned Node.js Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:102
Vulnerability Type: Uncontrolled third-party dependency installation
Risk Level: MediumVulnerable Code
bash cd {baseDir}/scripts && npm installA related dependency declaration appears at
SKILL.md:257:text | @linear/sdk | Node package | Required | npm install |Technical Analysis
The skill instructs users or agents to run
npm installin ascriptsdirectory, but the reviewed project contains onlySKILL.md. It does not contain the referenced directory, apackage.json, a lockfile, the advertised CLI implementation, pinned dependency versions, or package integrity metadata.Consequently, the dependency graph and any npm lifecycle scripts cannot be reviewed or reproduced. The command fails in the artifact as audited because the referenced directory is absent. However, if that directory is later supplied from an unreviewed source or created by another process, following the documented installation procedure could install uncontrolled package versions and execute lifecycle hooks such as
preinstall,install, orpostinstall.This finding does not establish that
@linear/sdkis malicious. The risk arises from directing installation without shipping a verifiable manifest, exact versions, integrity-protected lockfile, and auditable implementation.Attack Path
- A user or agent trusts the installation instructions in
SKILL.md. - A missing
scriptsdirectory is later obtained from an unreviewed source or populated by a process with write access to the project. - That directory contains a manipulated package manifest, malicious dependency, or npm lifecycle hook.
- The user or agent runs the documented
npm installcommand. - npm resolves the uncontrolled dependencies and may execute lifecycle scripts under the invoking user's account.
- Malicious installation code can act with the filesystem, net ...[truncated 652 chars]
- A user or agent trusts the installation instructions in
- Remediation
View remediation
Remediation Suggestions
- Include the complete claimed CLI implementation and its
scriptsdirectory in the reviewed package. - Supply a valid
package.jsonand an integrity-protected lockfile such aspackage-lock.json. - Pin dependencies to reviewed versions rather than relying on unconstrained resolution.
- Use
npm cifor deterministic installation instead ofnpm install. - Use
npm ci --ignore-scriptswhen lifecycle scripts are unnecessary. - If lifecycle scripts are required, document and audit each script before installation.
- Verify dependency provenance and package integrity in CI.
- Fail closed when the expected manifest, lockfile, or CLI files are absent rather than directing users to obtain unspecified external content.
- Run dependency installation in an isolated, minimally privileged environment without production credentials.
- Include the complete claimed CLI implementation and its
