T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned Third-Party CLI Execution and Unattended Global Skill Installation
- Content
View full analysis
` - Install a skill from GitHub or other sources - `npx skills check` - Check for skill updates - `npx skills update` - Update all installed skills ``` From `SKILL.md:50-58`: ```markdown ### Step 2: Search for Skills Run the find command with a relevant query: ```bash npx skills find [query] ``` ``` From `SKILL.md:86-90`: ```markdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add -g -y ``` ``` ### Technical Analysis The documented workflow invokes the `skills` package through `npx` without specifying an exact package version or verifying package integrity. Depending on the local package-manager state, `npx` may retrieve and execute the current package release from a remote registry. The security behavior of the command can therefore change after this skill has been reviewed. The workflow also permits installing skills from GitHub or unspecified “other sources.” No publisher allowlist, repository verification, immutable commit pin, signature check, checksum validation, source-code inspection, or permission review is required before installation. The installation command compounds this supply-chain exposure through the following options: - `-g` installs the downloaded skill globally at the user level, expanding its scope beyond the current project. - `-y` suppresses confirmation prompts that could otherwise provide an opportunity to inspect or reject the package. - `` may identify externally controlled content whose repository or branch can change after review. A malicious or compromis ...[truncated 2082 chars]- Remediation
View remediation
`. - Do not use floating tags such as `latest`. - Record and review version updates explicitly. 2. **Verify package provenance and integrity** - Use package-manager lockfiles and integrity hashes where supported. - Verify registry ownership, package signatures, release provenance, and repository identity. - Consider installing the reviewed CLI as a locked project dependency instead of downloading it dynamically for each invocation. 3. **Restrict acceptable skill sources** - Maintain an allowlist of trusted publishers and repositories. - Reject ambiguous package names, URL redirects, forks, and unapproved “other sources.” - Pin GitHub installations to immutable, reviewed commit hashes rather than mutable branches or tags. 4. **Inspect content before activation** - Download skills into an isolated staging directory first. - Review manifests, instruction files, scripts, hooks, dependencies, and requested permissions. - Scan downloaded content for remote execution, credential access, persistence, destructive commands, and instruction hijacking. 5. **Avoid unattended global installation** - Remove `-g` and install into a project-scoped or sandboxed directory by default. - Remove `-y` so the exact source and changes are presented before installation. - Require explicit informed user approval after displaying the publisher, repository URL, immutable revision, affected paths, and requested permissions. 6. **Apply execution isolation** - Run discovery and installation with minimal filesystem and network permissions. - Prevent access to credentials and sensitive environment variables during package execution. - Test newly installed skills in an isolated environment before making them available to normal agent sessions. 7. **Secur ...[truncated 213 chars]
