T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party CLI and Unverified Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-33 and 78-83
Vulnerability Type: Supply-chain exposure through unpinned executable dependencies and unverified external packages
Risk Level: MediumVulnerable Code
markdown **Key commands:** - `npx skills find [query]` - Search for skills interactively or by keyword - `npx skills add <package>` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skillsmarkdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add <owner/repo@skill> -g -yThe
-gflag installs globally (user-level) and-yskips confirmation prompts.text ### Technical Analysis The Skill directs the agent to execute `npx skills` without pinning the CLI package to a reviewed version or integrity digest. When the package is not already available locally, `npx` can retrieve and execute the currently published npm package, including package lifecycle behavior. The effective executable can therefore change after this Skill has been audited. The installation workflow accepts packages from GitHub or unspecified other sources without requiring repository allowlisting, immutable commit references, integrity verification, or a security review of the downloaded contents. It also recommends `-g`, which creates persistent user-level installation state, and `-y`, which suppresses the CLI confirmation prompt. This is a supply-chain weakness rather than evidence that the currently documented package is malicious. Exploitation depends on compromise or malicious control of the CLI package, a discovered Skill package, its repository, or another accepted distribution source. ### Attack Path 1. An attacker publishes or compromises a release of the package resolved by `npx skills`, or causes a malicious Skill package or repository to ap ...[truncated 1189 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to a specifically reviewed version, for example
npx skills@<approved-version>, and verify the package with a lockfile and trusted integrity digest where supported. - Maintain an allowlist of approved package owners, repositories, and registries. Do not permit installation from unspecified sources by default.
- Resolve GitHub-hosted Skills to reviewed immutable commit hashes rather than mutable branches, tags, or search-result identifiers.
- Download and inspect each Skill before installation, including its instructions, scripts, lifecycle hooks, dependencies, external URLs, and requested permissions.
- Require explicit, informed user approval after displaying the exact source, resolved version or commit, installation scope, and security implications.
- Remove
-yfrom the default workflow so confirmation is not automatically bypassed. - Avoid
-gby default. Install into an isolated project directory, sandbox, container, or other least-privilege environment. - Disable or restrict package lifecycle scripts where practical and run third-party tooling with limited filesystem, credential, and network access.
- Record and verify hashes of approved artifacts so unexpected upstream changes block installation.
- Pin the CLI to a specifically reviewed version, for example
