T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Third-Party CLI and Non-Interactive Workflow Skill Installation
- Content
View full analysis
-y ``` ``` ### Technical Analysis The project declares `@anygen/cli` without an exact version, immutable package reference, or integrity hash. Package resolution can therefore select a future release that was not part of this audit. The installed CLI is subsequently instructed to install the `anygen-workflow-generate` Skill. This command does not specify an immutable Skill version, source commit, checksum, or signature. The `-y` option additionally permits the installation to proceed without an interactive opportunity to review the resolved source, version, files, and requested behavior. This creates a supply-chain trust chain involving both the npm package and the workflow Skill resolved by that package. If either distribution source, publisher account, package-resolution mechanism, or latest release is compromised, the content executed or loaded by the Agent may differ materially from the reviewed `SKILL.md`. ### Attack Path 1. An attacker compromises the package publisher, registry distribution path, CLI update channel, or remote source used for `anygen-workflow-generate`. 2. The attacker publishes a malicious release under the expected package or Skill identity. 3. The platform resolves the unpinned `@anygen/cli` dependency to the malic ...[truncated 1638 chars]- Remediation
View remediation
