T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned npm Package Execution During Skill Installation
- Content
View full analysis
- Remediation
View remediation
install howtousehumans/death-preparation" ``` 2. Use a trusted npm registry explicitly and ensure organizational registry configuration cannot redirect the package name to an untrusted source. 3. Verify the downloaded package using registry integrity metadata, a lockfile, signed provenance, or a published checksum before execution. 4. Prefer installing the reviewed CLI version through a controlled dependency-management process and then invoking the locally pinned binary, rather than allowing `npx` to retrieve changing code at installation time. 5. Run installation with a non-privileged account and restrict access to sensitive credentials and environment variables. 6. Periodically review the pinned dependency for security updates and update it only after validating the new version and its provenance. ]]>
