T08 · Insecure Dependencies
- Location
SKILL.md:12- Finding
Unpinned npm Package Execution During Skill Installation
- Content
View full analysis
- Remediation
View remediation
install parenting-psychology" ``` 2. Verify the selected package version and its transitive dependencies through a lockfile or an equivalent reproducible dependency mechanism. 3. Validate the package against a known integrity digest before execution where the installation platform supports integrity verification. 4. Explicitly configure and document the trusted npm registry to reduce dependency-confusion and registry-substitution risks. 5. Review the package's lifecycle scripts and CLI entry point before approving a version. Disable lifecycle scripts where compatible with the installation workflow. 6. Run installation under a least-privileged account or sandbox with restricted filesystem, credential, and network access. 7. Establish a controlled update process in which newer package versions are audited before the pinned version is changed. ]]>
