T08 · Insecure Dependencies
- Location
README.md:17- Finding
Unpinned Remote Installation and Package Execution
- Content
View full analysis
Vulnerability Details
File Location:
README.md, lines 17–31
Vulnerability Type: Supply-chain exposure through mutable, unverified remote installation sources
Risk Level: MediumVulnerable Code
bash ### Claude Code # Clone the repository git clone https://github.com/gandli/space-query-skill.git ~/.claude/skills/space-query-skill ### Claude Code Plugin /plugin marketplace add gandli/space-query-skill /plugin install space-query-skill@gandli ### Other # Using skills CLI (recommended) npx skills add gandli/space-query-skillTechnical Analysis
The documented installation methods retrieve content from mutable third-party sources without pinning an immutable Git commit, an exact package version, or a signed release. No checksum or signature verification is required before the retrieved content is installed.
The
npxcommand presents additional exposure because it may download and execute an unpinned npm package. The Git and plugin installation methods place remotely controlled Skill content into an agent environment, where altered instructions may subsequently be loaded as trusted Skill instructions.This finding is limited to the installation guidance. The audited artifact itself contains no executable scripts, embedded malicious code, persistence mechanisms, credential theft, or confirmed malicious payload.
Attack Path
- An attacker compromises the referenced GitHub account or repository, npm package or package namespace, or plugin marketplace entry.
- The attacker replaces the legitimate package content with malicious Skill instructions or executable components.
- A user follows one of the documented installation commands.
- The installation client retrieves the attacker-controlled latest version because no immutable version or digest is specified.
- The altered package is installed into the user's agent environment.
- The agent later loads or invokes the compromised Skill, allowing the malicious content to act w ...[truncated 772 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin Git installation instructions to a reviewed commit hash or immutable signed release tag.
- Publish SHA-256 checksums or cryptographic signatures for release artifacts and require verification before installation.
- Pin the Skill and CLI package to exact versions rather than resolving the latest available version.
- Avoid direct execution through unpinned
npx. Prefer a locally installed, verified CLI or usenpx --no-installafter validating the package and lockfile. - Document the expected repository owner, package name, release digest, and signature-verification procedure to reduce namespace-confusion and account-compromise risks.
- Recommend reviewing the downloaded Skill manifest, instructions, and scripts before enabling it in an agent environment.
- Where supported, install Skills with restricted tool permissions and require explicit approval before running newly introduced scripts or network operations.
