T08 · Insecure Dependencies
- Location
SKILL.md:7- Finding
Unpinned Third-Party CLI Handles Sensitive Tokens and Tool Parameters
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill has a coherent tool-library purpose, but it asks users to install an unpinned CLI and pass API tokens on the command line without enough safeguards.
Review this skill before installing. Use only a trusted, pinned cogenticlink version, avoid putting real tokens in shared terminals or logs, check how ~/.cogenticlab/link/config.json is protected, and prefer narrowly scoped tokens you can revoke.
SKILL.md:7Unpinned Third-Party CLI Handles Sensitive Tokens and Tool Parameters
SKILL.md:23API Token Passed as a Command-Line Argument and Stored Without Documented Protection
The skill declares installation via an unpinned Node package and references execution through npx, which can pull whatever version is current at install or run time. In a security-sensitive skill that brokers remote CLI/API/MCP tool execution, this creates supply-chain risk because a compromised or breaking upstream release could alter behavior or execute malicious code on the host.
The skill instructs users to add and manage API tokens directly through CLI commands without any guidance on secret sensitivity, secure storage, redaction, or shell history exposure. Because this skill's core purpose is managing remote tool-library credentials, omission of token-handling safeguards materially increases the chance of accidental credential disclosure and subsequent unauthorized access to connected tools or services.
No suspicious patterns detected.