T08 · Insecure Dependencies
- Location
SKILL.md:57- Finding
Unpinned Third-Party Packages Are Downloaded and Executed
- Content
View full analysis
- Remediation
View remediation
`. - Declare tools as project development dependencies and execute their lockfile-resolved local binaries. - Commit and review the package lockfile, then use `npm ci` in automated environments. - Review dependency changes and lifecycle scripts before installation. - Require explicit user approval before an agent downloads or executes packages. - Use registry integrity, provenance, and allowlisting controls where available. - Run installation and build operations in an isolated environment with minimal credentials and filesystem access. ]]>
