T08 · Insecure Dependencies
- Location
SKILL.md:135- Finding
Execution of an Unpinned npm Installer from a Mutable Release Channel
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:135
Vulnerability Type: Unpinned third-party installer and mutable dependency resolution
Risk Level: HighVulnerable Code Snippet:
bash npx skillhub@latest install slack-toolkit-freeTechnical Analysis
The documented installation procedure uses
npxto download and execute the mutablelatestrelease of the externalskillhubnpm package. No exact version, integrity hash, lockfile, or provenance verification is specified.The effective code executed by this command can therefore change after the Skill has been reviewed. The project contains only
SKILL.mdand does not include the installer or Slack toolkit implementation, so the behavior of the downloaded code cannot be verified through this repository.This creates a supply-chain risk if the package publisher account, registry package, transitive dependency, or release process is compromised. npm package lifecycle scripts or the invoked CLI can execute code under the privileges of the user running the installation.
Attack Path
- An attacker compromises the
skillhubpackage, its publisher account, a transitive dependency, or the mutable release distributed aslatest. - A user follows the documented installation instructions.
npxresolves and downloads the attacker-controlled release.- npm executes applicable lifecycle scripts and the downloaded CLI with the invoking user's privileges.
- Malicious code can access files and environment variables available to that user.
- If
SLACK_BOT_TOKENis present in the environment or a readable.envfile, the code may steal it and use its granted Slack permissions.
Impact Assessment
Successful exploitation could result in arbitrary code execution under the local account that runs the installation command. The accessible scope may include:
- Files readable or writable by the invoking user.
- Environment variables an ...[truncated 570 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed version, for exampleskillhub@X.Y.Z. - Verify the selected package version's provenance, publisher, signatures, and registry metadata before documenting it.
- Use integrity verification or an approved lockfile where the installation workflow supports it.
- Avoid automatically executing npm lifecycle scripts unless they are required and have been reviewed.
- Prefer installing from a controlled internal registry or an immutable, verified artifact.
- Include the auditable implementation in the project or link to an immutable source revision so behavior can be reviewed.
- Run installation in a restricted environment without Slack tokens or unrelated credentials.
- Configure Slack tokens according to least privilege and rotate them immediately if installer compromise is suspected.
- Replace
