T08 · Insecure Dependencies
- Location
README.md:162- Finding
Unpinned Remote Installer and Mutable Skill Source
- Content
View full analysis
- Remediation
View remediation
add ... ``` 2. Pin the installed repository content to an immutable commit SHA or signed release tag if supported by the installer. 3. Publish and document expected commit identifiers and checksums for released skill artifacts. 4. Recommend installation with npm lifecycle scripts disabled where compatible: ```bash npm_config_ignore_scripts=true npx skills@ ... ``` 5. Verify the npm package publisher, provenance, and integrity before recommending a new version. 6. Require review of repository changes before updating the documented commit or release. 7. Avoid automatic confirmation flags such as `-y` in security-sensitive installation guidance unless the exact package and source revision are pinned. ]]>
