T08 · Insecure Dependencies
- Location
SKILL.md:15- Finding
Unpinned Third-Party Executable Dependencies
- Content
View full analysis
- Remediation
View remediation
``` 3. Update the Skill metadata so its installation declarations use the same reviewed versions rather than mutable package references. 4. Publish expected cryptographic checksums or signature-verification instructions and require users to verify downloaded artifacts before execution. 5. Document the reviewed package provenance, release date, source repository, and integrity information. 6. Avoid global installation where practical. Prefer an isolated environment, container, or dedicated low-privilege account with access only to the documents and output directories required for OCR. 7. Review npm lifecycle scripts, Go build dependencies, and transitive dependencies before approving each upgrade. Perform upgrades deliberately rather than automatically tracking the latest release. 8. Ensure that the OCR executable receives only the minimum required credentials and file access. Do not run installation or document processing as an administrator unless strictly necessary. ]]>
