T08 · Insecure Dependencies
- Location
SKILL.md:22- Finding
Execution of an Unpinned Third-Party npm CLI
- Content
View full analysis
- Remediation
View remediation
instructions ``` 2. Prefer declaring the CLI in a project `package.json`, committing the corresponding lockfile, and installing dependencies with: ```bash npm ci ``` Invoke the lockfile-resolved local executable afterward. 3. Verify package integrity and provenance during installation. Use npm integrity metadata, trusted publishing provenance where available, and an approved registry. 4. Review each intended CLI upgrade before changing the pinned version. Automated dependency updates should require security review and test validation. 5. Run the CLI with least privilege in an isolated environment. Limit filesystem access, environment variables, and network destinations to those required by the task. 6. Provide Skroll credentials only to the individual command that requires them rather than exporting them broadly into a long-lived shell environment. Use narrowly scoped and revocable credentials where supported. 7. Document the expected package version and checksum so operators can detect unexpected dependency changes before execution. ]]>
