T08 · Insecure Dependencies
- Location
SKILL.md:192- Finding
Unpinned Third-Party Dependencies and Mutable Installation Sources
- Content
View full analysis
- Remediation
View remediation
`. 3. Pin skill installations to immutable release identifiers or commit hashes where supported. 4. Publish and verify cryptographic hashes or signatures for downloaded artifacts. 5. Provide a lockfile or constraints file containing the complete resolved dependency graph and integrity metadata. 6. Avoid automatic upgrade flags in security-sensitive installation documentation. 7. Document the expected package publisher, repository, and network endpoints so users can verify provenance. 8. Run installation and execution in a least-privileged sandbox with restricted filesystem and network access. 9. Keep `CELLCOG_API_KEY` narrowly scoped, rotate it periodically, and prevent unnecessary child processes from inheriting it. 10. Review each dependency update before changing the pinned version, including installation hooks and transitive dependencies. ]]>
