T08 · Insecure Dependencies
- Location
SKILL.md:92- Finding
Unpinned Third-Party CLI Execution with Unattended Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, line 92
Vulnerability Type:T08: Insecure Dependencies
Risk Level: MediumVulnerable Code
bash npx skills add <owner/repo@skill> -g -yTechnical Analysis
The skill directs the agent to invoke the unpinned npm package
skillsthroughnpxand use it to install a skill obtained from GitHub or another external source. If the CLI is not already available locally,npxmay retrieve and execute the package version resolved by the registry at runtime.The command provides no exact CLI version, integrity hash, source allowlist, or mandatory package review. The
-goption installs the selected skill globally at user level, increasing its scope beyond the current project. The-yoption suppresses confirmation prompts, removing an opportunity to inspect the resolved source and installation behavior.Consequently, security depends on mutable external components: the npm package resolved as
skills, the package registry, the repository owner, and the selected skill contents. Compromise, dependency confusion, typosquatting, repository takeover, or a malicious search result could introduce executable code or hostile agent instructions.Attack Path
- A user asks the agent to locate a skill for a specialized task.
- The agent invokes the unpinned
npx skillsCLI, which may download and execute registry-provided package code. - Search results identify an attacker-controlled or compromised external skill.
- The agent runs
npx skills add <owner/repo@skill> -g -y. - Installation proceeds globally at user scope without an interactive confirmation step.
- Malicious install-time code could execute with the invoking user's privileges, or hostile skill instructions could influence subsequent agent activity.
Impact Assessment
Successful exploitation could execute code with the permissions of the user running the agent and in ...[truncated 557 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the Skills CLI to an exact, reviewed version rather than invoking an unversioned package, for example by using an approved version and validating its lockfile and integrity metadata.
- Separate discovery from installation. Search results should only be presented to the user until the exact repository, revision, and skill contents have been reviewed.
- Require explicit informed confirmation immediately before installation. Remove
-yso that source and scope can be checked before changes are made. - Default to project-local installation rather than
-g. Global installation should require a separate explanation and explicit opt-in. - Pin external skills to reviewed immutable commit hashes or signed releases instead of mutable branches or unqualified repository references.
- Restrict installation to an allowlist of trusted owners and repositories, and verify repository ownership and provenance.
- Inspect downloaded manifests, skill instructions, scripts, lifecycle hooks, and transitive dependencies before execution.
- Run installation in a sandbox with minimal filesystem, network, credential, and process permissions. Disable package lifecycle scripts where they are unnecessary.
- Record the resolved package version, source revision, integrity digest, and installation scope for later auditing.
