T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned npx Package Execution in Installation Metadata
- Content
View full analysis
- Remediation
View remediation
install howtousehumans/fire-skills ``` 2. Pin the installed skill to an immutable version, commit digest, or content hash if the installer supports it. 3. Prefer a lockfile-backed installation process with verified registry integrity metadata. 4. Configure npm to use an explicitly trusted registry and avoid environment-controlled registry substitution in privileged automation. 5. Install and review the CLI separately, then use `npx --no-install` or a directly referenced trusted local binary so installation cannot silently download a new release. 6. Run installation under a least-privileged account without unrelated credentials or sensitive environment variables. 7. Re-audit and verify checksums whenever either the CLI version or skill artifact changes. ]]>
