T08 · Insecure Dependencies
- Location
SKILL.md:195- Finding
Execution of an Unpinned Third-Party Package
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:195
Vulnerability Type: Supply-chain risk from a mutable dependency
Risk Level: MediumVulnerable Code Snippet:
bash npx skillhub@latest install slack-workspace-manager-proTechnical Analysis
The installation instruction uses
npxto retrieve and execute the mutablelatestversion of the third-partyskillhubpackage. No exact version, lockfile, package integrity hash, trusted publisher verification procedure, or reviewed local implementation is provided.Because
latestcan point to a different artifact after this skill has been audited, the code ultimately executed by this command is not fixed by the reviewed project. The repository contains onlySKILL.md; consequently, neither the installer implementation nor the installed Slack management skill can be inspected here. This creates a supply-chain trust gap rather than proof that the current upstream package is malicious.Attack Path
- An attacker compromises the package publisher account, registry distribution path, or a future release assigned to the
latesttag. - The attacker publishes or substitutes a modified
skillhubpackage containing malicious installer or lifecycle behavior. - A user follows the documented installation command.
npxdownloads the package currently referenced bylatestand executes its CLI, potentially including package lifecycle behavior.- The malicious package runs under the invoking user's local permissions and may install altered skill content or modify accessible resources.
Impact Assessment
Successful exploitation could grant an attacker the same local privileges as the user executing
npx. Depending on that user's environment and accessible credentials, this could permit reading or modifying files, accessing environment variables or Agent configuration, executing additional processes, and installing malicious skill instructions. ...[truncated 425 chars]- An attacker compromises the package publisher account, registry distribution path, or a future release assigned to the
- Remediation
View remediation
Remediation Suggestions
- Replace
@latestwith an exact, reviewed package version. - Record the dependency in a lockfile and verify registry-provided integrity metadata.
- Where practical, publish and verify a cryptographic checksum or signature for the approved package artifact.
- Document the expected registry and verified publisher identity to reduce dependency-confusion and package-substitution risks.
- Review the package's source, lifecycle scripts, transitive dependencies, and installer behavior before approving it.
- Disable package lifecycle scripts where compatible with the installation process.
- Execute installation in a restricted environment with minimal filesystem, credential, and network access.
- Include or vendor the actual skill implementation in the audited project so its behavior remains within the review boundary.
- Replace
