T08 · Insecure Dependencies
- Location
SKILL.md:92- Finding
Unpinned Global Installation of a Third-Party Slack Gateway CLI
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 92-95
Vulnerability Type: Supply-chain exposure through unpinned third-party dependencies
Risk Level: MediumVulnerable Code
bash # NPM npm install -g @slack-gateway/cli # ... # Or Homebrew brew install slack-gateway/cli/sgwTechnical Analysis
The Skill directs users or an Agent with execution privileges to globally install a third-party CLI without specifying an audited version, cryptographic checksum, package signature, or trusted source revision. A global NPM installation may execute package lifecycle scripts under the invoking user's privileges. The Homebrew command similarly resolves the formula available from its configured repository at installation time.
Because no version is pinned, the code installed during a future Skill invocation can differ from the component that existed when the Skill was audited. Compromise of the package publisher, registry account, formula repository, or distribution infrastructure could therefore introduce arbitrary executable code.
This behavior is needed only if the third-party CLI is chosen as the integration mechanism; global and unpinned installation is not the minimum privilege necessary to call Slack APIs.
Attack Path
- An attacker compromises the package publisher, NPM package, Homebrew formula, or associated distribution account.
- The attacker publishes a malicious version under the expected dependency name.
- A user or Agent follows the Skill and executes the unpinned installation command.
- The package manager resolves and installs the malicious current version.
- Installation hooks or later CLI execution run attacker-controlled code with the user's privileges.
- The malicious component can access files, environment variables, stored gateway credentials, and network resources available to that account.
Impact Assessment
Successful exploitation could result in a ...[truncated 287 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specific, security-reviewed version.
- Publish and verify cryptographic checksums or package signatures before installation.
- Identify the official publisher, source repository, and expected package provenance.
- Prefer a project-local installation over a global installation.
- Disable or carefully control package lifecycle scripts where possible.
- Use a lockfile or immutable artifact reference for reproducible deployment.
- Run the CLI in a sandbox or restricted service account without access to unrelated secrets.
- Establish a dependency update and vulnerability-review process before changing the pinned version.
