T03 · Remote Payload Retrieval and Execution
- Location
SKILL.md:13- Finding
Unpinned Remote Repository Retrieval and Unsafe Dependency Installation
- Content
View full analysis
- Remediation
View remediation
``` 2. Verify the checked-out commit or release against a trusted digest or signature before executing installation commands. 3. Require and review a committed lockfile, then replace `npm install` with deterministic installation: ```bash npm ci --ignore-scripts ``` 4. Audit all dependencies and lifecycle scripts. If lifecycle scripts are operationally required, explicitly allow only reviewed scripts rather than enabling arbitrary package hooks. 5. Vendor the reviewed implementation with the Skill or distribute a signed, versioned release artifact so that the executed code matches the audited code. 6. Run installation and rendering in a restricted environment with: - A dedicated unprivileged account. - Minimal filesystem access. - No unnecessary credentials or secrets. - Restricted outbound network access. - A disposable workspace or container. 7. Re-audit the pinned source and dependency lockfile whenever the approved version changes. ]]>
