T08 · Insecure Dependencies
- Location
README.md:91- Finding
Unpinned Third-Party Installer and Mutable Skill Source
- Content
View full analysis
- Remediation
View remediation
add ``` 2. Replace the mutable skill reference with an immutable commit hash or cryptographically verified release. 3. Publish and verify integrity hashes or signed release artifacts before installation. 4. Review the resolved package, transitive dependencies, and lifecycle scripts before recommending the command. 5. Use a lockfile or equivalent dependency manifest where the installation mechanism supports it. 6. Disable package lifecycle scripts during installation when they are unnecessary and the package manager supports doing so. 7. Run installation in a sandbox or least-privilege environment without access to production credentials or sensitive user files. 8. Document the exact CLI version, source revision, expected integrity value, and verification procedure so users install the same artifact that was audited. ]]>
