T08 · Insecure Dependencies
- Location
SKILL.md:240- Finding
Unpinned Third-Party Packages and Skills Are Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
add skill ... ``` 2. Pin each remote skill to an immutable release or commit hash rather than a mutable repository head. 3. Record and verify cryptographic hashes or signed provenance for every downloaded skill. 4. Use a committed lockfile and an approved internal registry or package mirror. 5. Download dependencies into a staging directory and inspect their scripts before execution. 6. Disable package lifecycle scripts during retrieval where supported, then explicitly execute only reviewed entry points. 7. Run installation in a sandbox with restricted filesystem and network access. 8. Grant installed skills only the minimum required workspace and tool permissions. 9. Treat the optional cross-agent sharing component as a separate trust decision and require explicit informed approval before installation. 10. Document the exact reviewed versions and establish a controlled dependency-update process. ]]>
