T08 · Insecure Dependencies
- Location
SKILL.md:5- Finding
Unpinned Global npm Packages Create Supply-Chain Code-Execution Risk
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This cost-tracking skill is broadly coherent, but it needs Review because it adds broad workflow monitoring, an API-intercepting cache proxy, and dashboard command controls without enough scoping or data-handling detail.
Install only if you are comfortable with a globally installed npm CLI recording agent activity and repository metadata. Avoid enabling the proxy for secrets, customer data, or regulated prompts until retention, cache purge, and access-control behavior are clear. Prefer a pinned reviewed package version and do not run installation commands with elevated privileges unless needed.
SKILL.md:5Unpinned Global npm Packages Create Supply-Chain Code-Execution Risk
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
# Standard cloud model (cost auto-calculated):
cs log-ai -p anthropic -m claude-sonnet-4 --prompt-tokens 8000 --completion-tokens 2000 --json
# Local model with compute duration (NEW in v3.3.0):
# Use --duration in seconds (120) or string (2m30s). Cost is based on registered $/hr rate.
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
# Local model with compute duration (NEW in v3.3.0):
# Use --duration in seconds (120) or string (2m30s). Cost is based on registered $/hr rate.
cs log-ai -p ollama -m llama3 --tokens 4500 --duration 2m30s --local --json
# With all fields:
cs log-ai -p openai -m gpt-4o --prompt-tokens 5000 --completion-tokens 1500 -c 0.04 --agent "Research Agent" --json
Skill selects an external model or provider that may use a different account or billing plan than the operator expects. Undisclosed model switches can cause unexpected cost or quota consumption.
cs log-ai -p ollama -m llama3 --tokens 4500 --duration 2m30s --local --json
cs log-ai -p openai -m gpt-4o --prompt-tokens 5000 --completion-tokens 1500 -c 0.04 --agent "Research Agent" --json
**Agent Name:** Use `--agent "Agent Name"` to track which agent performed the work.
The semantic caching proxy is described as intercepting API calls but the documentation does not warn that prompt and response content may transit, be cached, or otherwise be handled by the proxy. That omission is dangerous because users may route sensitive LLM traffic through it without understanding the confidentiality, retention, or replay implications.
The skill advertises automatic tracking of file changes and git commits but does not foreground a clear warning that local repository activity will be monitored and recorded. This creates a privacy and data-governance risk, especially in sensitive repos where filenames, commit metadata, or change history may themselves be confidential.
Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.
>
> | OS | Install build tools |
> |---|---|
> | **Ubuntu/Debian** | `sudo apt-get install -y build-essential python3` |
> | **macOS** | `xcode-select --install` |
> | **Windows** | `npm install -g windows-build-tools` or install Visual Studio Build Tools |
> | **Alpine** | `apk add build-base python3` |
The repeated 'Always' guidance encourages invocation for nearly every multi-step task and after each API call, causing pervasive monitoring behavior by default. In practice this can normalize broad collection of workflow metadata, token usage, file changes, and git activity without case-by-case user awareness or minimization.
The documented dashboard capabilities include real-time CLI execution and granular session termination, which are operational control features beyond simple cost and audit tracking. In a skill presented as observability tooling, these controls create a broader attack surface and could enable command execution or disruption if exposed without strong authorization and clear user consent.
The skill documents a semantic caching proxy that intercepts API traffic and can serve cached responses, which expands the skill from passive cost tracking into active handling of prompts and responses. Because no safeguards, scoping limits, or data-handling warnings are provided, users may unknowingly route sensitive model inputs/outputs through a local interception layer that could retain or replay sensitive data.
No suspicious patterns detected.