T08 · Insecure Dependencies
- Location
shared/tool-instructions.md:23- Finding
Automatic Execution of an Unpinned Remote Security Scanner
- Content
View full analysis
- Remediation
View remediation
scan --skill ``` Use the exact syntax supported by the selected package ecosystem. 2. Where supported, verify the downloaded artifact using a cryptographic hash, lockfile, signed provenance, or trusted publisher signature. 3. Require explicit user confirmation before the first network retrieval or execution: - Display the package name, exact version, registry, and data supplied to it. - Explain that the command may access the network and execute third-party code. - Allow the user to continue with built-in local checks only. 4. Prefer a previously installed and explicitly trusted executable instead of resolving a package dynamically during an audit. 5. Run third-party scanners with reduced privileges: - Restrict filesystem access to the selected Skill. - Pass only required environment variables. - Apply network restrictions where practical. - Avoid forwarding the Agent's complete environment. 6. Update `SECURITY.md` and the declared trust model to disclose optional network calls and third-party execution accurately. 7. Record the exact scanner version in evaluation output so results are reproducible and auditable. ]]>
