T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned npm CLI Dependency Permits Mutable Supply-Chain Code Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent Cargo segmentation skill, but it should be reviewed carefully because it installs a mutable npm CLI and can access, export, and modify authenticated workspace audience data.
Before installing, pin and review the Cargo CLI version instead of using `latest`, run it in a least-privileged environment, prefer email or OAuth login for interactive use, protect any CI token outside command history and logs, confirm the active workspace before writes, and treat fetched records, signed download URLs, and troubleshooting transcripts as sensitive customer data.
SKILL.md:13Unpinned npm CLI Dependency Permits Mutable Supply-Chain Code Execution
SKILL.md:34API Token Is Accepted Directly Through a Command-Line Argument
The manifest description lists trigger phrases like "save this as a list" and "narrow this down to," which are common conversational phrases that could apply in many contexts beyond Cargo segmentation. Although some examples are domain-related, these broad phrases are not narrowly constrained enough to clearly limit when the skill should activate.
The skill instructs users to run npx @cargo-ai/cli without pinning a version, which can fetch and execute the latest published package at runtime. That creates a supply-chain risk: a compromised or malicious upstream release could be executed immediately in the user's environment, and the bootstrap section explicitly involves authenticated CLI use against workspace data, increasing blast radius.
The skill documentation instructs users to sign in using email, OAuth, or API token and later describes downloading full datasets via signed URL, but it does not explicitly warn that these actions may involve sensitive workspace data or credential handling. Because this is a markdown file, user-facing safety disclosures about privacy-impacting behavior are expected when the skill can access or export user data.
This markdown file includes a natural-language instruction that enforces a French spelling (conjonction) as the required key. Under the policy rule, forcing a specific language or locale without opt-in can be a violation unless the locale constraint is clearly justified; here it is presented as a requirement but not explicitly justified as an API compatibility constraint.
No suspicious patterns detected.