T08 · Insecure Dependencies
- Location
SKILL.md:89- Finding
Unpinned Third-Party Package Installation Creates a Supply-Chain Execution Risk
- Content
View full analysis
Vulnerability Details
File Locations:
SKILL.md:89template-filling-execution.md:80-83CONNECTORS.md:17-19
Vulnerability Type: Unpinned and unverified third-party dependencies
Risk Level: MediumVulnerable Code Snippets
SKILL.md:89:markdown (install: `npx skills add open-agreements/open-agreements`).template-filling-execution.md:80-83:markdown - Easiest: configure the remote MCP (see Step 1) - Alternative: install Node.js 20+ and `npm install -g open-agreements`CONNECTORS.md:17-19:markdown ### Alternative: Local CLI For fully local execution (no network calls during fills), install [`open-agreements` from npm](https://www.npmjs.com/package/open-agreements). Requires Node.js >= 20. See the [README](https://github.com/open-agreements/open-agreements#use-with-claude-code) for details.Technical Analysis
The documented installation commands retrieve mutable third-party content without pinning an exact audited version or verifying its integrity. The project does not include a lockfile, checksum, signature, provenance requirement, or vendored implementation against which the downloaded content can be validated.
In particular,
npm install -g open-agreementsresolves the package version available under the package registry's current metadata. npm packages may contain installation lifecycle scripts that execute during installation. A global installation also makes the resulting executable broadly available in the user's environment.The
npx skills add open-agreements/open-agreementsinstruction similarly retrieves external skill content by a mutable package or repository identifier rather than an immutable audited revision. Consequently, the code or instructions installed when a user follows the documentation may differ from the content that was originally reviewed.This is a supply-chain weakness rather than evidence that the referenced ...[truncated 1741 chars]
- Remediation
View remediation
Remediation Suggestions
-
Pin the CLI to an exact reviewed release rather than resolving the latest version:
bash npm install --global --ignore-scripts open-agreements@<audited-exact-version>Only use
--ignore-scriptsif the audited package does not legitimately require lifecycle scripts. -
Avoid global installation where possible. Prefer a project-local dependency installed under a dedicated, least-privileged environment.
-
Pin skill installation to an immutable release tag or commit digest supported by the installer rather than a mutable repository identifier.
-
Publish and document cryptographic checksums or signed provenance for approved artifacts. Verify downloaded content before execution.
-
Use a lockfile with integrity metadata for local dependency installations, and review transitive dependency changes before updating the approved version.
-
Document the expected package publisher, source repository, exact version, and verification procedure so users can detect typosquatting or registry compromise.
-
Run installation and document generation as a non-privileged user without unnecessary access to credentials or sensitive directories.
-
Establish a controlled upgrade process that audits each new package version and updates the pinned version only after review.
-
