T08 · Insecure Dependencies
- Location
SKILL.md:69- Finding
Unpinned Global Installation of a Third-Party npm CLI
- Content
View full analysis
- Remediation
View remediation
``` 2. Include and verify the expected npm package integrity digest or signed provenance before installation. 3. Document the verified package publisher, registry, source repository, and release-signing process. 4. Prefer a project-local or isolated installation over a global installation. 5. Where operationally possible, disable lifecycle scripts during installation and separately review any required installation steps: ```bash npm install --ignore-scripts socialclaw@ ``` 6. Review each dependency update before changing the pinned version. 7. Consider bundling a reviewed client implementation or using the documented HTTPS API directly, avoiding unnecessary execution of external package code. 8. Explicitly warn users not to run the installation as root or through `sudo`. ]]>
