T08 · Insecure Dependencies
- Location
SKILL.md:28- Finding
Unpinned Third-Party CLI Execution and Unattended Global Skill Installation
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 28–31 and 78–82
Vulnerability Type: Unreviewed third-party package execution and installation
Risk Level: MediumVulnerable Code
markdown **Key commands:** - `npx skills find [query]` - Search for skills interactively or by keyword - `npx skills add <package>` - Install a skill from GitHub or other sourcesmarkdown If the user wants to proceed, you can install the skill for them: ```bash npx skills add <owner/repo@skill> -g -ytext ### Technical Analysis The documented workflow invokes the `skills` CLI through `npx` without pinning the CLI to a reviewed version or verifying its integrity. If the package is not already available locally, `npx` may download and execute package code obtained from an external package registry. The effective CLI implementation can therefore change after this skill has been reviewed. The workflow also permits installation from GitHub or other third-party sources without requiring an allowlist, immutable commit reference, signature, checksum, provenance verification, or source review. The recommended `-g -y` flags install the selected skill globally at the user level and suppress interactive confirmation. This broadens the installation scope and removes an opportunity for the user to inspect or reject the operation. This constitutes an insecure dependency and supply-chain pattern. A compromised CLI release, registry account, upstream repository, mutable branch, or misleading search result could cause attacker-controlled package content to be downloaded and installed. ### Attack Path 1. A user asks the agent to locate functionality available as an installable skill. 2. The agent follows `SKILL.md` and runs the unpinned `npx skills find [query]` command. 3. `npx` retrieves and executes the current external CLI package if it is not already installed locally. 4. The external search pr ...[truncated 1246 chars]- Remediation
View remediation
Remediation Suggestions
- Pin the
skillsCLI to a specifically reviewed version rather than invoking an unversioned package, for example through a controlled project dependency and lockfile. - Verify package integrity and provenance using registry integrity metadata, signatures, checksums, and trusted publisher information where available.
- Restrict skill discovery and installation to an explicit allowlist of trusted organizations and repositories.
- Require immutable commit hashes or signed release tags instead of mutable branches or unpinned repository references.
- Review downloaded skill files and any installation hooks before executing or installing them.
- Install skills locally and with the minimum necessary scope by default. Avoid
-gunless global installation is explicitly required. - Remove
-yand require informed user confirmation that identifies the exact source, version or commit, requested scope, and reviewed contents. - Separate discovery from installation: searching may be automated, but installation should require a distinct approval step.
- Run package retrieval and inspection in a restricted environment with limited filesystem, network, credential, and process permissions.
- Maintain an audit record containing the selected repository, immutable revision, integrity value, review result, and approving user.
- Pin the
