T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Executable npm Dependency
- Content
View full analysis
(CI) cargo-ai whoami # confirm the active workspace before any write ``` The troubleshooting guide repeats the unsafe installation guidance: ```markdown | `command not found: cargo-ai` | CLI not installed or not in PATH | Run `npm install -g @cargo-ai/cli` or prefix with `npx @cargo-ai/cli` | ``` ### Technical Analysis The Skill installs `@cargo-ai/cli@latest` or executes the package through `npx` without an exact version or integrity constraint. The `latest` npm distribution tag is mutable, so the effective executable can change after the Skill has been reviewed. A global npm installation also increases exposure because package installation scripts and the installed executable run with the invoking user's permissions and remain available outside the immediate Skill invocation. The project contains no lockfile, checksum, integrity metadata, or local implementation that would allow the reviewed Skill to guarantee which CLI code will execute. The package name and declared GitHub organization are internally consistent, and the audit found no evidence that the current package is malicious. The vulnerability is therefore an unsafe supply-chain trust model rather than proof of an active malicious dependency. ### Attack Path 1. A user or Agent loads the Skill on a sy ...[truncated 1298 chars]- Remediation
View remediation
