T08 · Insecure Dependencies
- Location
SKILL.md:24- Finding
Unpinned Third-Party CLI Execution and Non-Interactive Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 24-30, 48-58, and 80-84
Vulnerability Type: Supply-chain exposure through unpinned packages and insufficiently verified skill sources
Risk Level: MediumVulnerable Code
SKILL.md, lines 24-30:bash npx skills find [query] npx skills add <package> npx skills check npx skills updateSKILL.md, lines 48-58:bash npx skills find [query]For example:
- User asks "how do I make my React app faster?" →
npx skills find react performance - User asks "can you help me with PR reviews?" →
npx skills find pr review - User asks "I need to create a changelog" →
npx skills find changelog
SKILL.md, lines 80-84:bash npx skills add <owner/repo@skill> -g -yThe
-gflag installs globally (user-level) and-yskips confirmation prompts.Technical Analysis
The skill directs the agent to execute
npx skillswithout specifying an exact package version or validating package integrity. Depending on the local npm cache and registry resolution,npxcan download and execute the currently resolved version of the package. Consequently, the effective executable is not immutable at the time this skill is reviewed.The CLI is then used to discover and install skills from GitHub or other sources. The documented workflow does not require repository allowlisting, immutable commit pinning, signature verification, integrity verification, or inspection of the downloaded skill before installation. The recommended installation command also combines global installation (
-g) with confirmation suppression (-y), reducing user visibility and extending the installed component's scope beyond the current project.This is an insecure dependency and supply-chain pattern rather than evidence that the currently referenced CLI or repositories are malicious.
Attack Path
- An attacker compromises the npm packa ...[truncated 1466 chars]
- User asks "how do I make my React app faster?" →
- Remediation
View remediation
Remediation Suggestions
- Pin the CLI to an audited, exact version, for example
npx --package=skills-cli@X.Y.Z, using the correct verified package name and version for the ecosystem. - Enforce package-lock integrity metadata or an equivalent cryptographic verification mechanism before execution.
- Restrict skill discovery and installation to an explicit allowlist of trusted organizations and repositories.
- Pin installed skills to immutable commit hashes rather than mutable branches, tags, or search-result identifiers.
- Download and inspect skill manifests, instructions, scripts, lifecycle hooks, and dependency declarations before installation or execution.
- Install skills locally and within a sandbox by default. Global installation should require a separate, informed user decision.
- Remove
-yfrom the recommended command so that the package, source, version, requested scope, and intended changes can be reviewed before installation. - Require explicit user approval before running updates because updates can replace previously reviewed content.
- Execute package installation with minimal privileges, restricted filesystem access, limited environment variables, and controlled network access.
- Record the verified source repository, immutable revision, hashes, and audit result for every installed skill.
- Pin the CLI to an audited, exact version, for example
