T08 · Insecure Dependencies
- Location
SKILL.md:155- Finding
Execution of Unpinned npm Packages During Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:155
Vulnerability Type: Supply-chain risk from mutable, unpinned npm dependencies
Risk Level: MediumVulnerable Code Snippet:
bash # Install the tool npx skillhub@latest install slack-workspace-manager-freeTechnical Analysis
The installation procedure invokes
skillhub@latestthroughnpx. Thelatesttag is mutable, so the executed package version can change after this skill has been reviewed. The command also does not specify an integrity hash, lockfile, trusted package digest, or reviewed version ofslack-workspace-manager-free.npxcan download and execute package-controlled code. Consequently, the effective installation logic is supplied by an external package registry at execution time rather than being fully represented by the audited project. A compromised maintainer account, registry package, release process, or malicious future version could therefore cause arbitrary code to run under the invoking user's privileges.This finding is limited to the unsafe dependency-installation instruction. The audit did not establish that the current external packages are malicious because their source code and registry artifacts were not included in the project.
Attack Path
- An attacker compromises the
skillhubpackage, its publisher, or its release pipeline, or causes a malicious release to receive the mutablelatesttag. - A user or Agent follows the documented installation procedure.
npxretrieves the attacker-controlled package version from the configured npm registry.- Package-controlled code executes with the privileges and environment of the user running the Agent.
- The code could read accessible local files, alter installed components, or tamper with the Slack-management CLI.
- If the compromised component remains involved when the user completes Slack OAuth authorization, it could attempt to access the result ...[truncated 787 chars]
- An attacker compromises the
- Remediation
View remediation
Remediation Suggestions
- Replace
skillhub@latestwith an exact, reviewed version, and pin the installed skill to an exact version as well. - Commit and enforce a lockfile where the installation model supports one.
- Verify package integrity using registry integrity metadata, cryptographic hashes, signatures, or provenance attestations.
- Use an approved registry or internal mirror and restrict installation to allowlisted package names, versions, and publishers.
- Review downloaded package contents and lifecycle scripts before execution. Disable lifecycle scripts where they are unnecessary.
- Run installation in a sandbox or least-privileged environment without unrelated credentials or sensitive files.
- Separate installation from Slack authorization so install-time processes cannot access OAuth credentials.
- Document the expected package source, exact version, checksums, required Slack scopes, and secure token-storage mechanism.
- Replace
