T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Package Execution in Installation Command
- Content
View full analysis
- Remediation
View remediation
install workplace-injury-rights" ``` 2. Verify the selected package version through a trusted registry source and review its provenance before publishing the instruction. 3. Provide and verify package integrity metadata or cryptographic signatures where the installation platform supports them. 4. Document the expected package publisher, registry, version, and checksum so users can detect substitution. 5. Prefer a trusted installation mechanism that does not download and immediately execute mutable remote code. 6. Run installation with least privilege in an isolated environment; users should not execute the command as `root` or with unnecessary administrative permissions. ]]>
