T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned npm CLI Package Allows Mutable Supply-Chain Execution
- Content
View full analysis
- Remediation
View remediation
install outdoor-recreation-skills" ``` 2. Verify the selected package version against a trusted integrity digest and preserve that verification in a lockfile or controlled installation manifest. 3. Require the official npm registry explicitly in controlled automation, and reject unexpected registry configuration or package provenance. 4. Run installation under a dedicated least-privilege account without access to production credentials, sensitive user files, or privileged system locations. 5. Prefer a preinstalled and centrally managed installer over downloading and executing an npm package at installation time. 6. Review each installer upgrade before changing the pinned version, including its CLI entry point, lifecycle scripts, transitive dependencies, and published provenance. 7. Where supported, use a trusted internal package mirror or allowlist that exposes only approved package versions. ]]>
