T08 · Insecure Dependencies
- Location
SKILL.md:14- Finding
Unpinned npm CLI Dependency Allows Mutable Upstream Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This Cargo observability skill is coherent for creating scheduled alerts, but it should be reviewed because it installs a mutable npm CLI and can create scheduled actions that run agents, tools, or connectors.
Review the dependency policy before installing: prefer a pinned, reviewed @cargo-ai/cli version, use a Cargo token limited to observability permissions where possible, preview alerts before creating them, and be careful with actions because breaches can trigger paid connector, tool, or agent runs on a schedule.
SKILL.md:14Unpinned npm CLI Dependency Allows Mutable Upstream Code Execution
The trigger phrases are very broad and overlap with normal conversational requests such as 'notify me if', 'let me know when', and 'set up monitoring'. In an agent-routing context, that can cause the skill to activate unexpectedly on ambiguous prompts, leading to unintended monitoring configuration, writes to observability resources, or scheduled actions being created without the user clearly intending to use this specific skill.
The skill explicitly recommends running the CLI via npx @cargo-ai/cli without a pinned version, which can fetch whatever package version is current at execution time. That creates supply-chain and reproducibility risk: a compromised or breaking upstream release could be pulled into a user workflow unexpectedly, especially because this skill is centered on operational automation and alerting.
No suspicious patterns detected.