T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Third-Party CLI and Unattended Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 27–32 and 83–89
Vulnerability Type: Supply-chain exposure through unpinned dependencies and unsafe installation defaults
Risk Level: MediumVulnerable Code
markdown - `npx skills find [query]` - Search for skills interactively or by keyword - `npx skills add <package>` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skillsmarkdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add <owner/repo@skill> -g -yThe
-gflag installs globally (user-level) and-yskips confirmation prompts.text ### Technical Analysis The instructions invoke `npx skills` without pinning the CLI to an audited version. Depending on the local npm environment, `npx` may retrieve and execute the currently published package, meaning its implementation can change after this skill has been reviewed. The skill also permits packages from GitHub or unspecified “other sources” and recommends installation using `-g -y`. Global installation expands the package's user-level scope, while `-y` suppresses interactive confirmation. The instructions do not require verification of repository ownership, immutable commit identifiers, package integrity hashes, signatures, or downloaded skill contents before installation. This creates a supply-chain trust gap: a compromised package release, malicious repository, dependency-confusion event, typosquatted source, or manipulated search result could cause attacker-controlled components or instructions to be installed. ### Attack Path 1. A user asks the agent to locate a skill for a specialized task. 2. The agent invokes the unpinned `npx skills` CLI, potentially downloading and executing the currently published version. 3. The CLI or search service presents an attacker-controlled or compromised skill as a relevant result. 4. The user agre ...[truncated 1043 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a reviewed, explicit version, such as
npx skills@<approved-version>, and verify package integrity through an approved lockfile, checksum, or signature mechanism. - Restrict installations to an allowlist of trusted owners and repositories.
- Reference immutable commit hashes or signed release tags rather than mutable branches or unqualified package identifiers.
- Inspect the complete downloaded skill package, including scripts, hooks, dependencies, and instruction files, before installation.
- Avoid global installation by default. Prefer a project-local, isolated, or sandboxed installation with minimal filesystem, network, and credential access.
- Remove
-yfrom the recommended command. Require explicit confirmation that displays the resolved source, version or commit, requested scope, and relevant installation behavior. - Separate discovery from installation so search results are never installed automatically.
- Revalidate provenance and integrity before updates, and do not perform unrestricted bulk updates of installed skills.
- Pin the CLI to a reviewed, explicit version, such as
