T08 · Insecure Dependencies
- Location
SKILL.md:17- Finding
Unpinned External npm Package Is Installed Globally and Can Be Updated to a Mutable Latest Release
- Content
View full analysis
- Remediation
View remediation
``` 2. Publish the complete CLI source code alongside the Skill so that executable behavior can be included in security review. 3. Provide and verify an integrity digest, signed provenance statement, or trusted npm provenance record for every approved release. 4. Audit and lock all transitive dependencies. Include a lockfile in the source distribution and use reproducible release procedures. 5. Avoid global installation where practical. Prefer a project-local, isolated installation with a restricted execution environment and least-privilege filesystem access. 6. Disable npm lifecycle scripts during installation when they are not required: ```bash npm install --ignore-scripts @kg-ai/kugou-skill@ ``` If lifecycle scripts are required, document and audit each script before installation. 7. Require explicit user confirmation immediately before both initial installation and every update. Display the exact version, registry, and command that will be executed. 8. Do not automatically trust the `latest` distribution tag. Retrieve available release metadata, validate it against an approved version list and integrity record, and only then perform the update. 9. Document recovery procedures for removing a compromised global installation, rotating locally stored authentication secrets, and reinstalling a known-good release. ]]>
