T08 · Insecure Dependencies
- Location
SKILL.md:58- Finding
Unpinned Global Installation of an External Executable
- Content
View full analysis
- Remediation
View remediation
``` 2. Replace `@latest` with an immutable, reviewed Go module version or commit. 3. Publish and verify SHA-256 checksums or signed release attestations before execution. 4. Provide reproducible-build metadata and software-bill-of-materials information. 5. Avoid global installation where possible. Run the CLI in an isolated environment with only the filesystem and network access it requires. 6. Vendor or bundle the reviewed implementation when feasible so the effective executable payload matches the audited artifact. 7. Restrict permissions on `~/.botwallet/config.json` and `~/.botwallet/seeds/`, and prevent unrelated processes from reading them. 8. Require explicit user approval before installing or upgrading executable dependencies. ]]>
