T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Unpinned Third-Party CLI Execution and Unverified Global Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` From `SKILL.md`, lines 87–93: ```markdown ### Step 4: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` ``` ### Technical Analysis The skill instructs the agent to invoke `npx skills` without specifying an exact package version or verifying package integrity. When the package is unavailable locally, `npx` may retrieve and execute the package resolved by the configured npm registry. Consequently, the code executed at audit time may differ from the code executed later. The instructions also permit skills to be installed from GitHub or unspecified “other sources.” They do not require verification of the repository owner, immutable commit, release signature, checksum, package contents, or install scripts. The recommended `-g -y` options increase risk by installing at user-global scope and suppressing interactive confirmation. This creates a supply-chain trust boundary in which a compromised package, malicious source repository, dependency-confusion package, or typo-squatted package could cause attacker-controlled code to execute under the account running the agent. ### Attack Path 1. An attacker publishes, replaces, or compromises the package resolved as `skills`, one of its transitive dependencies, or a skill repository returned by the external discovery service. 2. A user asks the agent to find or install a relevant skill. 3. Following `SKILL.md`, the agent executes an unpinne ...[truncated 1390 chars]- Remediation
View remediation
`, and update the version only through a controlled review process. 2. Verify registry provenance, release signatures where available, and package integrity hashes before execution. 3. Use an organizational allowlist of approved package owners, repositories, and skill identifiers. 4. Resolve GitHub installations to reviewed immutable commit hashes rather than mutable branches or tags. 5. Inspect package contents, manifests, lifecycle scripts, and transitive dependencies before installation. 6. Remove `-g -y` from the default workflow. Prefer local, isolated installation with explicit user confirmation. 7. Run discovery and installation in a sandbox with minimal filesystem, credential, environment-variable, and network access. 8. Present the resolved source, exact version or commit, requested scope, and security implications to the user before installation. 9. Disable or tightly control package lifecycle scripts where supported. 10. Document a rollback procedure for removing installed skills and restoring affected user-level configuration. ]]>
