T08 · Insecure Dependencies
- Location
SKILL.md:129- Finding
Unpinned Package Execution Through npx
- Content
View full analysis
- Remediation
View remediation
my-video ``` - Document the expected npm registry and advise users to verify package ownership and provenance. - Prefer installing through a project manifest and committed lockfile rather than executing a freshly resolved package directly. - Use npm provenance, integrity metadata, and dependency scanning where supported. - Review package lifecycle scripts and transitive dependencies before using the command in sensitive environments. - Run scaffolding tools in a restricted development container without production credentials or unnecessary filesystem access. ]]>
