T08 · Insecure Dependencies
- Location
SKILL.md:6- Finding
Mutable and Unpinned Packages Are Executed Through npx
- Content
View full analysis
--json ``` ```bash npx @openant-ai/cli@latest tasks review \ --application \ --accept \ --comment "Great portfolio! Looking forward to your work." \ --json ``` ```bash npx @openant-ai/cli@latest tasks verify \ --submission \ --approve \ --comment "Perfect work! Exactly what we needed." \ --json ``` From `references/skills-ecosystem.md`: ```markdown - **[skills.sh](https://skills.sh/)** — Open Agent Skills Directory. Install: `npx skills add --skill ` - **[ClawHub](https://clawhub.ai/)** — Skill dock for agents. Install: `npx clawhub@latest install ` ``` ```bash # PDF handling npx skills add anthropics/skills --skill pdf # Code review npx skills add skillcreatorai/ai-agent-skills --skill code-review # Find skills for a task npx skills add vercel-labs/skills --skill find-skills ``` ### Technical Analysis The skill repeatedly instructs the agent to execute `@openant-ai/cli@latest` through `npx`. The `@latest` tag is mutable, so the code executed during a future invocation is not necessarily the version that existed when this skill was audited. If the package publisher account, registry, release p ...[truncated 3257 chars]- Remediation
View remediation
install npx --yes skills@ add --skill ``` 3. Pin repository-based skills to immutable commit hashes or signed release artifacts rather than branches, tags that can be moved, or repository names alone. 4. Prefer a preinstalled and independently reviewed CLI over downloading code during each skill invocation. Manage it through a lockfile and a controlled build or deployment process. 5. Verify package integrity using registry integrity metadata, trusted checksums, provenance attestations, or cryptographic signatures. Record the expected digest alongside the approved version. 6. Disable or carefully review dependency lifecycle scripts during installation where feasible. Install dependencies in a restricted build environment rather than in the agent's operational environment. 7. Run the OpenAnt CLI with least privilege in an isolated environment. Restrict filesystem access, environment-variable exposure, and outbound network access to the minimum required endpoints. 8. Separate read-only review operations from state-changing commands. Require explicit user confirmation immediately before application acceptance, rejection, submission approval, or any operation that releases escrow. 9. Maintain an approved dependency inventory and periodically review pinned updates before changing versions. Re-audit the resolved package and its transitive dependency tree for each upgrade. ]]>
