T08 · Insecure Dependencies
- Location
SKILL.md:895- Finding
Unpinned Third-Party Packages in the Blockchain Signing Path
- Content
View full analysis
- Remediation
View remediation
@proton/js@ npm install --save-exact @proton/web-sdk@ ``` 2. Pin the CLI to a reviewed version and avoid global installation where practical: ```bash npm install --save-dev --save-exact @proton/cli@ ``` Invoke it through a controlled project-local path or `npm exec` with lockfile enforcement. 3. Explicitly declare and pin `@xpr-agents/openclaw` if it is required by the examples. Ensure the documented installation instructions match all imported packages. 4. Commit a `package-lock.json` generated from reviewed dependencies and use: ```bash npm ci --ignore-scripts ``` Enable lifecycle scripts only for packages that have been reviewed and demonstrably require them. 5. Verify package provenance, publisher identity, npm registry source, signatures or attestations, and integrity metadata before installation. 6. Run dependency installation and blockchain interaction under a dedicated, least-privileged operating-system account or isolated environment. 7. Use narrowly scoped blockchain permissions instead of an unrestricted `active` permission where supported. Apply transaction-value limits, contract/action restrictions, multisignature approval, or hardware-backed confirmation for high-value operations. 8. Require users to inspect the account, contract action, recipient, token quantity, and authorization permission before approving each transaction. 9. Add automated dependency scanning and update review procedures. Do not accept automated dependency upgrades into the signing path without security review and transaction-level regression testing. ]]>
