T08 · Insecure Dependencies
- Location
SKILL.md:148- Finding
Unpinned Third-Party Package Execution via Mutable npm Tag
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 148
Vulnerability Type: Supply-chain risk caused by executing an unpinned third-party package
Risk Level: MediumVulnerable Code:
bash npx skillhub@latest install slack-hub-tool-freeTechnical Analysis
The installation instructions invoke
skillhubthroughnpxusing the mutable@latesttag. If the package is not already available locally,npxcan download package content from the configured npm registry and execute its CLI code. npm lifecycle scripts may also execute during package installation.Because
@latestdoes not identify an immutable, audited release, the code executed by users can differ from the version considered during this audit. The project does not specify an exact package version, integrity hash, trusted registry, signature-verification process, or lifecycle-script restriction.This creates an insecure dependency boundary: compromise of the package publisher, npm account, registry resolution, or a future release could replace the effective installation payload without requiring any change to this reviewed file.
Attack Path
- An attacker compromises the
skillhubpackage publisher account, its release pipeline, or another relevant dependency in its supply chain. - The attacker publishes a malicious version and assigns or causes npm to assign the
latestdistribution tag to it. - A user follows the documented command in
SKILL.md. npxresolvesskillhub@latest, downloads the attacker-controlled version, and executes its CLI or associated installation scripts.- The malicious process runs with the permissions of the user who invoked the command.
- It may access files and environment variables available to that user, including a configured
SLACK_BOT_TOKEN, and perform unauthorized local or network operations.
Impact Assessment
Successful exploitation could provide arbitrary code executi ...[truncated 738 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
-
Replace
@latestwith an exact, reviewed version, for example:bash npx --yes skillhub@X.Y.Z install slack-hub-tool-free -
Verify the selected package version and its transitive dependencies before recommending it.
-
Publish and validate package integrity hashes or cryptographic signatures through a documented verification procedure.
-
Explicitly specify the trusted npm registry and use a lockfile where the installation workflow permits it.
-
Disable npm lifecycle scripts with
--ignore-scriptsif the package can operate without them. -
Prefer a locally installed, locked, and reviewed CLI rather than downloading executable code at invocation time.
-
Run installation with a minimally privileged account in an isolated environment that does not expose Slack credentials or unrelated files.
-
Document package ownership, provenance, and the process used to review upgrades before changing the pinned version.
-
