T08 · Insecure Dependencies
- Location
SKILL.md:13- Finding
Unpinned CLI Dependency Executed During Installation
- Content
View full analysis
- Remediation
View remediation
install howtousehumans/basic-plumbing-troubleshooting" ``` 2. Verify the selected package version and its provenance before publishing the installation instruction. 3. Where supported, verify the downloaded package against a trusted integrity hash or signed release. 4. Use a lockfile and deterministic dependency installation for any maintained installer wrapper. 5. Run installation with least privilege in a restricted environment that does not expose unrelated credentials, sensitive files, or privileged sockets. 6. Avoid running the installer with `sudo`, as an administrator, or from a privileged CI account. 7. Periodically re-audit the pinned CLI before intentionally updating the version. ]]>
