T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party CLI and Unattended Global Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The skill instructs the agent to execute `npx skills` without pinning the CLI to a reviewed version. Depending on the local npm environment, `npx` may download and execute the package dynamically. The effective CLI implementation can therefore differ from the version that existed when this skill was audited. The installation target is also selected from external search results and may originate from GitHub or other unspecified sources. The workflow does not require an immutable commit, version pin, checksum, signature, source allowlist, repository-ownership validation, or inspection of the downloaded skill before installation. The suggested `-g -y` flags compound the exposure: `-g` creates a persistent user-level installation, while `-y` suppresses interactive confirmation. Consequently, a compromised registry package, malicious repository, dependency-confusion package, typosquatted package, or manipulated search result could cause attacker-controlled package lifecycle code or hostile agent instructions to be ...[truncated 1486 chars]- Remediation
View remediation
