T08 · Insecure Dependencies
- Location
SKILL.md:25- Finding
Unpinned External Package Execution and Unattended Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 25-30, 50, and 75-79
Vulnerability Type: Supply-chain exposure through unpinned package execution and unsafe external installation
Risk Level: HighVulnerable Code Snippets:
markdown **Key commands:** - `npx skills find [query]` - Search for skills interactively or by keyword - `npx skills add <package>` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skillsbash npx skills find [query]markdown ### Step 4: Offer to Install If the user wants to proceed, you can install the skill for them: ```bash npx skills add <owner/repo@skill> -g -ytext ### Technical Analysis The skill directs the agent to execute `npx skills` without specifying an exact, reviewed package version or validating package integrity. Depending on the local npm configuration and cache state, `npx` may retrieve and execute the package from an external registry. Consequently, the code ultimately executed can change after this skill has been reviewed. Search results can identify skills hosted in external repositories, and the installation procedure does not require an approved publisher, immutable commit identifier, checksum, signature, or source-code review. The recommended `-g -y` flags further increase exposure: `-g` installs the selected skill at user scope, while `-y` suppresses confirmation prompts. Globally installed skill instructions may subsequently be available to other projects or agent sessions. This is a supply-chain weakness rather than evidence that the currently referenced CLI or repositories are malicious. Exploitation depends on compromise, replacement, typosquatting, or malicious publication of the npm package or a selected external skill. ### Attack Path 1. An attacker publishes a malicious package or skill, compromises ...[truncated 1541 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an exact reviewed version, for example by using an exact npm version rather than an unconstrained
npx skillsinvocation. - Verify package integrity with a lockfile, registry integrity hash, or cryptographic signature before execution.
- Maintain an allowlist of approved publishers and repositories. Do not install arbitrary search results without provenance validation.
- Pin external skills to immutable commit hashes or signed releases rather than mutable branches or tags.
- Remove
-yso that installation requires an explicit approval step after displaying the exact source, version, requested scope, and relevant security implications. - Avoid
-gby default. Prefer a project-local, isolated installation that cannot affect unrelated projects or future sessions. - Download and statically inspect the selected skill and any executable scripts before installation or activation.
- Run discovery and installation tools in a sandbox with restricted filesystem, credential, process, and network access.
- Separate discovery from installation: search may be automated, but installation should require explicit user authorization for the exact immutable artifact.
- Define a controlled update policy. Updates should be reviewed and integrity-verified rather than applied automatically from mutable upstream sources.
- Pin the CLI to an exact reviewed version, for example by using an exact npm version rather than an unconstrained
