T08 · Insecure Dependencies
- Location
SKILL.md:57- Finding
Automatic Execution of Unpinned Latest-Version Packages
- Content
View full analysis
" ``` The Python execution reference similarly prescribes: ```bash uvx --refresh --from rollinggo@latest rollinggo --help uvx --refresh --from rollinggo@latest rollinggo search-hotels \ --origin-query "Find hotels near Tokyo Disneyland" \ --place "Tokyo Disneyland" --place-type "" ``` ### Technical Analysis The skill explicitly requires executing the current `latest` release from npm or PyPI. No exact version, integrity hash, lockfile, trusted artifact digest, or reviewed package snapshot is provided. The `npx --yes` option suppresses interactive package-installation confirmation. The `uvx --refresh` option deliberately refreshes the package cache, allowing a newly published package to replace the version previously reviewed or executed. The global installation alternatives also modify the user's persistent executable environment. Because the project contains only documentation and no source code for the downloaded `rollinggo` package, the audit cannot verify what the fetched package executes, which network destinations it contacts, or how it handles inherited environment variables. This does not prove that the current package is malicious, but it creates an unsafe mutable-code exec ...[truncated 1597 chars]- Remediation
View remediation
