T08 · Insecure Dependencies
- Location
SKILL.md:52- Finding
Unpinned Third-Party Skill Installation Creates Supply-Chain Risk
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 52-58
Vulnerability Type: T08: Insecure Dependencies
Risk Level: MediumComplete Code Snippet:
bash # Install skills distilled by SkillAlchemy npx skills add agentsope/SkillAlchemy/skills/<skill-name> # Install a persona skill distilled by Nuwa npx skills add alchaincyf/nuwa-skill # Install book-based skills distilled by Cangjie npx skills add kangarooking/cangjie-skillTechnical Analysis
The documented commands invoke an npm-resolved CLI through
npxwithout pinning its package version and install content from third-party GitHub repositories without immutable commit hashes, release versions, checksums, or signature verification.Consequently, the content executed or installed when a user follows these instructions may differ from the content available when this project was audited. Compromise of the npm package, a referenced repository, a maintainer account, or a mutable upstream branch could turn the installation workflow into a supply-chain delivery channel.
The project contains documentation only, and there is no evidence that the referenced upstream projects are currently malicious. The risk arises from the unpinned and unverified trust relationship.
Attack Path
- An attacker compromises the npm-resolved
skillspackage, one of the referenced GitHub repositories, or an associated maintainer account. - The attacker publishes malicious installer behavior or modifies content on the mutable upstream reference.
- A user follows one of the documented
npx skills addcommands. npxresolves the unpinned CLI, and the CLI retrieves the current third-party repository content.- Attacker-controlled code or skill instructions are installed or processed with the permissions available to the CLI and Agent environment.
- Depending on the delivered payload, the attacker may manipulate Agent behavior or access file ...[truncated 618 chars]
- An attacker compromises the npm-resolved
- Remediation
View remediation
Remediation Suggestions
- Pin the npm CLI to a specific audited version rather than relying on its current default resolution:
bash npx skills@<audited-version> add ... - Pin every GitHub dependency to an immutable, reviewed commit hash or cryptographically signed release where the installer supports such references.
- Publish expected checksums or signatures and verify downloaded artifacts before installation.
- Add an explicit review step requiring users to inspect all retrieved scripts, manifests, hooks, and Agent instructions before activation.
- Run installation in a sandbox or least-privileged environment without unnecessary credentials, sensitive environment variables, or elevated permissions.
- Maintain an allowlist of approved upstream versions and periodically re-audit them before updating the pinned references.
- Pin the npm CLI to a specific audited version rather than relying on its current default resolution:
