T08 · Insecure Dependencies
- Location
SKILL.md:42- Finding
Unpinned Remote Package Retrieval and Execution
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:42-45references/project-setup.md:17-30references/project-setup.md:41-43references/project-setup.md:239-242references/deployment-and-advanced.md:26-45references/styling-and-theming.md:124-138references/troubleshooting.md:391-393references/troubleshooting.md:423-429
Vulnerability Type: Execution of unpinned third-party npm packages
Risk Level: MediumVulnerable Code
SKILL.md:42-45:bash npm create astro@latest -- --template starlightreferences/project-setup.md:17-30:bash # npm npm create astro@latest -- --template starlight # pnpm pnpm create astro --template starlight # yarn yarn create astro --template starlightbash npm create astro@latest -- --template starlight/tailwindreferences/project-setup.md:41-43:bash npx astro add starlightreferences/project-setup.md:239-242:bash npx @astrojs/upgradereferences/deployment-and-advanced.md:26-45:bash npx astro add vercelbash npx astro add netlifybash npx astro add cloudflarereferences/styling-and-theming.md:124-138:bash npm create astro@latest -- --template starlight/tailwindbash npx astro add tailwindbash npm install @astrojs/starlight-tailwindreferences/troubleshooting.md:391-393:bash npx @astrojs/upgradereferences/troubleshooting.md:423-429:bash npx astro --version npm list @astrojs/starlightbash npx @astrojs/upgradeTechnical Analysis
The Skill repeatedly recommends
npm create,npx,pnpm create, andyarn createcommands without pinning reviewed package versions. The@latestspecifier explicitly retrieves whichever release is current when the command is run. Depending on package-manager behavior and local inst ...[truncated 2049 chars]- Remediation
View remediation
Remediation Suggestions
-
Replace floating versions and
@latestwith explicitly reviewed versions, for example:bash npm create astro@5.14.1 -- --template starlight npx @astrojs/upgrade@0.4.4The exact versions should be selected and updated through the project's dependency-review process.
-
Install required tools as declared project dependencies rather than retrieving them ad hoc:
bash npm install --save-dev astro@<reviewed-version> -
Commit a reviewed lockfile and use reproducible installation commands such as:
bash npm ci -
Require lockfile integrity checks in CI and reject unexpected dependency-tree changes.
-
Review package provenance, publisher identity, release signatures where available, and lifecycle scripts before approving upgrades.
-
Consider disabling lifecycle scripts during initial inspection:
bash npm install --ignore-scriptsEnable required scripts only after reviewing them.
-
Document that package-manager commands must run as an unprivileged user in a project-scoped environment, never with
sudo. -
For automated agents, require explicit user approval before downloading or executing a package version that is not already present in the reviewed lockfile.
-
