T08 · Insecure Dependencies
- Location
README.md:43- Finding
Unpinned npm Installer Executes Mutable Third-Party Code Without Confirmation
- Content
View full analysis
- Remediation
View remediation
add bryant24hao/oc-doctor -g ``` 2. Publish and document the expected package name, version, registry, source repository, and integrity digest. 3. Verify the downloaded package against a trusted checksum or lockfile before execution. 4. Avoid suppressing confirmation for security-sensitive installation steps where practical. 5. Consider providing a non-executing installation method, such as downloading a versioned release archive and verifying its checksum before copying the skill files. 6. Apply the corrected command consistently in both README files and both user-story documents. ]]>
