T08 · Insecure Dependencies
- Location
SKILL.md:29- Finding
Unpinned CLI Execution and Unreviewed Global Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` ```bash npx skills find [query] ``` ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` The `-g` flag installs globally (user-level) and `-y` skips confirmation prompts. ``` ### Technical Analysis The Skill instructs the Agent to execute the `skills` npm package through `npx` without specifying a reviewed package version or integrity value. Depending on local npm behavior and cache state, `npx skills` may retrieve and execute a currently published package version from an external registry. The effective CLI implementation can therefore change after this Skill has been reviewed. The CLI is then used to discover and install additional Skills from GitHub or unspecified “other sources.” The recommended installation command combines global user-level installation (`-g`) with automatic confirmation (`-y`). This makes it possible to install third-party content persistently without an interactive confirmation step or a documented source-review procedure. The project does not itself contain a malicious payload, scripts, credential access, or an implemented exfiltration mechanism. The risk arises from its unsafe supply-chain workflow and delegated trust in mutable external packages and repositories. ### Attack Path 1. An attacker publishes a malicious or compromised version of the npm package resolved by `npx skills`, compromises a repository returned by the search ...[truncated 1595 chars]- Remediation
View remediation
find ``` Maintain a documented review process before changing that version. 2. Where supported, verify registry provenance and package integrity using a lockfile, integrity hash, trusted registry configuration, and package-signing or provenance information. 3. Restrict installation sources to an explicit allowlist of reviewed owners and repositories. Do not permit arbitrary GitHub repositories or unspecified external sources by default. 4. Remove `-y` from installation commands so the user can review the exact source, version, destination, and requested changes before installation. 5. Avoid global installation by default. Prefer a project-scoped or isolated installation so an untrusted Skill cannot automatically become available across unrelated projects and sessions. 6. Before installation, retrieve the candidate into a quarantined directory and review all instruction files, scripts, manifests, dependencies, lifecycle hooks, network behavior, and requested permissions. 7. Require explicit user authorization immediately before installation. Search or discovery consent should not be treated as installation consent. 8. Execute package discovery and installation in a sandbox with restricted filesystem, network, environment-variable, and credential access. 9. Record the installed repository, immutable commit hash, Skill identifier, and reviewed content digest. Updates should require a new review rather than automatically trusting the latest upstream state. ]]>
