T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned Cargo CLI Dependency Permits Unreviewed Supply-Chain Changes
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill matches its stated Cargo connector-management purpose, but it handles credentials and mutable CLI installation in ways users should review carefully.
Review this skill before installing in production or shared agent environments. Prefer a pinned @cargo-ai/cli version, avoid pasting real tokens or connector API keys into command lines or chat, and treat connector list/get JSON as potentially sensitive because it may include credential config for non-credit connectors. Rotate any credentials accidentally exposed in logs or transcripts.
SKILL.md:13Unpinned Cargo CLI Dependency Permits Unreviewed Supply-Chain Changes
SKILL.md:36Authentication Tokens and Connector API Keys Are Passed Through Command-Line Arguments
references/response-shapes.md:5Connector Enumeration May Expose Stored Integration Credentials in Standard Output
The skill instructs users to run npx @cargo-ai/cli, which resolves and executes the latest package version at runtime rather than a pinned, reviewed release. That creates a supply-chain risk: if the upstream package is compromised or a breaking/malicious update is published, users may execute untrusted code during connector setup and authentication flows.
The example shows credential material being passed directly on the command line in JSON (for example, an apiKey in --config) without any warning about secret exposure. Command-line arguments are commonly captured in shell history, process listings, logs, and support transcripts, so users may unintentionally leak live connector credentials while following the documentation.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Connectors
| Symptom | Cause | Fix |
| --------------------------------------- | ------------------------------------------------ | ------------------------------------------------------------------------------------------------ |
| `connector get` returns not found | Wrong UUID | Re-run `connector list` to get the correct UUID |
| `connector create` fails | Integration slug doesn't exist | Run `integration list` to find valid `integrationSlug` values |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
## Connector autocomplete
| Symptom | Cause | Fix |
| ---------------------------------------------------- | ------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------- |
| `connector autocomplete` returns empty results | Wrong autocomplete slug or params | Re-check the `uiSchema` from `integration get <slug>` — use the exact `ui:options.slug` and pass required `params` |
| `Invalid autocomplete params` error | Missing or wrong params keys | Check `ui:options.params` in the `uiSchema` — each key listed there must be provided in `--params` with an actual value |
Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.
| `Invalid autocomplete params` error | Missing or wrong params keys | Check `ui:options.params` in the `uiSchema` — each key listed there must be provided in `--params` with an actual value |
| `connectorNotFound` reason | Wrong connector UUID | Re-run `connector list` to get the correct UUID |
| `failedToGetIntegration` reason | Integration doesn't support autocomplete for this slug | Verify the autocomplete slug exists in the integration's `uiSchema` — not all fields use autocomplete |
| Stale or outdated autocomplete results | Results are cached (default 30 minutes) | Pass `--refresh` to bypass the cache |
| Used a freeform value instead of autocomplete result | Field requires a specific value from the autocomplete result set | Always check `uiSchema` for `IntegrationAutocompleteWidget` — if present, fetch and use a `value` from the autocomplete results |
## Integrations
The document states that when useCredits is false, config contains integration-specific credentials, but it does not include any caution about sensitive secret handling, storage, or exposure. Because this is a markdown file and it documents behavior affecting credentials, a brief user warning would improve disclosure of privacy and security impact.
No suspicious patterns detected.