T08 · Insecure Dependencies
- Location
Skill.md:90- Finding
Unverified Third-Party Skill Installation with Global and Non-Interactive Flags
- Content
View full analysis
Vulnerability Details
File Location:
Skill.md, lines 90-95
Vulnerability Type: Supply-chain exposure through unpinned and unverified third-party installation
Risk Level: MediumVulnerable code snippet:
markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add <owner/repo@skill> -g -yThe
-gflag installs globally (user-level) and-yskips confirmation prompts.text ### Technical Analysis The skill directs the agent to invoke an unpinned `npx skills` package and install third-party content identified by an externally supplied repository and skill name. The broader instructions explicitly state that skills can come from GitHub or other sources, but do not require source validation, version or commit pinning, integrity verification, content inspection, or an allowlist. Using `npx` without a pinned package version can retrieve the current package release at execution time. The effective CLI implementation may therefore differ from the version that was previously reviewed. Likewise, the referenced skill can change if it is resolved through a mutable branch or tag. The `-g` option expands the installation scope to the user's global skill environment, while `-y` suppresses confirmation prompts that could otherwise provide an opportunity to review the source and destination. These behaviors create a supply-chain risk if a package, repository, maintainer account, search result, or dependency is compromised or impersonated. ### Attack Path 1. An attacker publishes or compromises a skill repository, package, or dependency accepted by the Skills CLI. 2. The malicious skill appears in search results or is supplied to the agent as an installation candidate. 3. The user agrees to installation without receiving immutable source, integrity, or provenance information. 4. The agent executes `npx skills add <owner/repo@skill> -g -y`. 5. `npx` retrie ...[truncated 824 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the Skills CLI to a reviewed version, such as
skills@<exact-version>, instead of resolving the latest mutable release. - Pin installed skills to immutable commit hashes or cryptographically verified releases.
- Restrict installations to an explicit allowlist of trusted owners, repositories, and registries.
- Verify package provenance, signatures, checksums, ownership, and repository history before installation.
- Inspect downloaded skill instructions and scripts before loading or executing them.
- Remove
-yso that installation requires an explicit confirmation after presenting the exact source, revision, requested scope, and security implications. - Avoid
-gby default. Prefer an isolated, project-local, sandboxed installation with minimal filesystem and network permissions. - Run installation in a restricted environment that does not expose unrelated credentials or sensitive files.
- Document a rollback procedure and maintain an inventory of installed skill versions and source revisions.
- Pin the Skills CLI to a reviewed version, such as
