T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned and Unauditable Executable Dependency Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:10-18; additional instances inREADME.md:5-8,README.md:24-30, andREADME.md:40-44
Vulnerability Type: Unpinned third-party executable dependency
Risk Level: MediumVulnerable Code
SKILL.md:10-18:bash ## Install ContentStudio CLI if it doesn't exist ```bash npm install -g contentstudio-cli # or pnpm install -g contentstudio-clinpm release: https://www.npmjs.com/package/contentstudio-cli contentstudio-agent github: https://github.com/contentstudioio/contentstudio-agent
text `README.md:5-8`: ```bash **Install as a skill:** ```bash npx skills add contentstudioio/contentstudio-agenttext `README.md:24-30`: ```bash ### From npm (recommended) ```bash npm install -g contentstudio-cli # or pnpm install -g contentstudio-clitext `README.md:40-44`: ```bash ```bash npx skills add contentstudioio/contentstudio-agenttext ### Technical Analysis The Skill instructs an agent or operator to install and execute the current registry version of `contentstudio-cli` globally. It also invokes an external package through `npx` without pinning a commit, package version, or integrity digest. The audited project contains only documentation and does not include the CLI source code, `package.json`, a lockfile, or a bundled executable. Therefore, the effective executable payload cannot be verified from this artifact and may change after the Skill has been reviewed. The claimed credential redaction, TLS validation, endpoint handling, file permission enforcement, and dry-run protections consequently cannot be independently confirmed. This is especially significant because the installed CLI is expected to receive: - `CONTENTSTUDIO_API_KEY` - A Bluesky app password - Connected social-account and workspace identifiers - Customer inbox messages and contact details - Local files selected for media up ...[truncated 2689 chars]- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI version
- Replace mutable installation commands with an exact audited version, for example:
bash npm install -g contentstudio-cli@1.5.0 - Do not use version ranges or implicit
latest.
- Replace mutable installation commands with an exact audited version, for example:
-
Verify package integrity
- Publish and document the expected npm integrity digest.
- Verify the downloaded package tarball against that digest before installation.
- Sign releases and publish verifiable provenance or build attestations.
-
Pin Skill retrieval
- Pin
npx skills addto a reviewed package version or immutable Git commit. - Avoid retrieving mutable repository branches during automated installation.
- Pin
-
Include auditable implementation materials
- Include the CLI source,
package.json, lockfile, and build configuration in the review artifact. - Ensure the distributed npm bundle can be reproducibly built from the audited source.
- Include the CLI source,
-
Avoid global installation
- Prefer project-local installation with a lockfile.
- Execute the pinned binary through a constrained package script or an explicitly versioned
npxinvocation. - Run it in a sandbox or container with access only to required files and environment variables.
-
Minimize credential scope
- Use a dedicated API key with only the workspaces and operations required for the task.
- Do not expose unrelated environment variables to the CLI process.
- Rotate the API key and Bluesky app password after any suspected package compromise.
-
Constrain network destinations
- Enforce an allowlist for the production ContentStudio API hostname.
- Disable or tightly restrict
CONTENTSTUDIO_BASE_URLand--base-urloverrides in production agent environments so authenticated traffic cannot be redirected to an attacker-controlled endpoint.
-
Harden package execution
- Disable dependency installation scripts where feasible ...[truncated 222 chars]
-
