T08 · Insecure Dependencies
- Location
SKILL.md:44- Finding
Automatic Execution of an Unpinned npm Dependency
- Content
View full analysis
- Remediation
View remediation
`. 2. Record the dependency in a package manifest and lockfile rather than resolving it dynamically through an unpinned `npx` command. 3. Verify package integrity using the package manager's lockfile integrity metadata or an independently validated checksum. 4. Remove `-y` where practical so that unexpected downloads or package changes require explicit approval. 5. Review the selected package version, including its executable entry point and npm lifecycle scripts, before deployment. 6. Monitor advisories and publisher changes for the pinned dependency, then upgrade only after reviewing and testing each new version. 7. Run the MCP process with least privilege in an isolated environment, exposing only the files, environment variables, and network destinations necessary for dictionary operations. ]]>
