T08 · Insecure Dependencies
- Location
SKILL.md:31- Finding
Unpinned Third-Party Package Execution During Installation
- Content
View full analysis
- Remediation
View remediation
@`. 2. Use a lockfile and npm integrity metadata where installation is managed as part of a Node.js project. 3. Verify the expected package publisher, registry, and provenance before execution. 4. Prefer an installation mechanism that downloads a versioned artifact and verifies its cryptographic checksum or signature before running it. 5. Document that installation commands must not be executed with administrator or root privileges. 6. Apply the corrected installation instructions consistently in both `SKILL.md` and `README.md`. ]]>
