T08 · Insecure Dependencies
- Location
SKILL.md:80- Finding
Unpinned Third-Party Package Installation Instructions
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 80-94
Vulnerability Type: Unpinned and unverifiable third-party dependencies
Risk Level: MediumComplete Code Snippet
bash npm install express # Install package npm uninstall lodash # Uninstall package npm update # Update all packages npm outdated # Check outdated packages npm audit fix # Fix vulnerabilities npm ci # Install from package-lock in CI pip install django # Install package pip uninstall numpy # Uninstall package pip list --outdated # List outdated packages pip freeze > requirements.txt # Export dependencies pip install -r requirements.txt # Install dependencies in bulk pip check # Check dependency conflictsTechnical Analysis
The Skill recommends installing third-party npm and Python packages without requiring exact version pins, integrity hashes, a reviewed lockfile, or a restricted package registry. Commands such as
npm install expressandpip install djangoresolve mutable package versions and transitive dependencies at execution time. The security properties of the installed code can therefore differ from those present when the Skill was reviewed.The requirements-file command is also unsafe when the referenced file is untrusted or lacks exact versions and hashes. A malicious or compromised package may execute installation hooks, build backends, or other package-controlled code. The
npm updateandnpm audit fixexamples can additionally change dependency versions beyond those already reviewed.These commands are documentation examples and are not executed automatically by the project. Exploitation therefore requires an Agent or user to follow the instructions in an environment where a malicious dependency, registry response, lockfile, or requirement ...[truncated 1466 chars]
- Remediation
View remediation
Remediation Suggestions
- Require exact package versions rather than unconstrained package names.
- For npm, prefer
npm ciwith a reviewed and committed lockfile instead ofnpm installor broadnpm updateoperations. - For Python, use a reviewed requirements file containing exact versions and verified hashes, then install with:
bash python -m pip install --require-hashes -r requirements.txt - Configure trusted registries explicitly and reject unexpected package indexes or registry overrides.
- Review transitive dependencies, package ownership, release history, and installation scripts before installation.
- Run package managers as an unprivileged user in an isolated virtual environment or container.
- Require explicit user confirmation before installing or updating dependencies, especially in CI or production environments.
- Avoid automated broad fixes such as
npm audit fixunless the resulting dependency changes have been reviewed and tested.
