T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party CLI Execution and Unattended Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 23–30, 57, 91, and 101
Vulnerability Type: Supply-chain exposure through unpinned runtime dependencies and unsafe third-party installation
Risk Level: MediumVulnerable Code Snippets
markdown The Skills CLI (`npx skills-gitcode`) is the package manager for the open agent skills ecosystem. **Key commands:** - `npx skills-gitcode find [query]` - Search for skills interactively or by keyword - `npx skills-gitcode add <package>` - Install a skill from GitHub or other sources - `npx skills-gitcode check` - Check for skill updates - `npx skills-gitcode update` - Update all installed skillsbash npx skills-gitcode find [query]bash npx skills-gitcode add vercel-labs/agent-skills@react-best-practicesbash npx skills-gitcode add <owner/repo@skill> -g -yTechnical Analysis
The Skill instructs the agent to execute
skills-gitcodethroughnpxwithout pinning an exact reviewed package version or validating package integrity. Depending on local npm behavior and cache state,npxmay retrieve and execute package content from the configured registry at runtime. Consequently, the code executed can differ from the code that existed when this Skill was reviewed.The installation workflow also permits packages from “GitHub or other sources” and recommends
-g -y. The-goption broadens the installation scope to the user-level global environment, while-ysuppresses the confirmation prompt that would otherwise provide a final review point.The document recommends checking installation counts, repository stars, and source reputation. Those signals can assist selection, but they do not provide cryptographic integrity, immutable versioning, provenance verification, or a security review of the installed content. A popular or reputable dependency can still be compromised.
Attack Path
- A user asks the agent to discover or install functionality provided by ...[truncated 1528 chars]
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact, independently reviewed version, for example
npx skills-gitcode@X.Y.Z, rather than resolving the latest available release. - Use a lockfile or equivalent integrity mechanism and verify package checksums, signatures, provenance attestations, publisher identity, and the canonical source repository.
- Maintain an explicit allowlist of approved Skill repositories, versions, and commit hashes. Do not permit arbitrary “other sources” by default.
- Download and statically inspect each Skill’s instructions, scripts, dependencies, hooks, and installation behavior before enabling or executing it.
- Remove
-yfrom the default workflow and require explicit, informed user approval immediately before installation. - Avoid
-gby default. Install into an isolated, task-specific environment with minimum filesystem, credential, process, and network permissions. - Resolve GitHub-based installations to immutable reviewed commit hashes rather than mutable branches or tags.
- Treat installation counts, stars, and author reputation only as supplementary indicators, not as security controls.
- Add rollback and removal procedures for installed Skills and record the exact source, version, hash, and approval associated with every installation.
- Pin the CLI to an exact, independently reviewed version, for example
